Alcatel 9000 Betriebsanweisung Seite 354

  • Herunterladen
  • Zu meinen Handbüchern hinzufügen
  • Drucken
  • Seite
    / 702
  • Inhaltsverzeichnis
  • LESEZEICHEN
  • Bewertet. / 5. Basierend auf Kundenbewertungen
Seitenansicht 353
Configuring DHCP Security Features Configuring DHCP Relay
page 18-18 OmniSwitch 6800/6850/9000 Network Configuration Guide June 2006
the trust mode for a port is configured to block or allow all DHCP traffic. See “Configuring the Port Trust
Mode” on page 18-18 for more information.
In addition, the following functionality is also activated by default when DHCP Snooping is enabled:
The DHCP Snooping binding table is created and maintained.
MAC address verification is performed to compare the source MAC address of the DHCP packet with
the client hardware address contained in the packet.
Option-82 data is inserted into the packet and then DHCP reply packets are only sent to the port from
where the DHCP request originated, instead of flooding these packets to all ports.
To enable or disable any of the above functionality at the switch level, use the following commands:
Note the following when disabling DHCP Snooping functionality:
Disabling Option-82 is not allowed if the binding table is enabled.
Enabling the binding table is not allowed if Option-82 data insertion is not enabled at either the switch
or VLAN level.
VLAN-Level DHCP Snooping
To enable DHCP Snooping at the VLAN level, use the ip helper dhcp-snooping vlan command. For
example, the following command enables DHCP Snooping for VLAN 200:
-> ip helper dhcp-snooping vlan 200
When this feature is enabled at the VLAN level, DHCP Snooping functionality is only applied to ports that
are associated with a VLAN that has this feature enabled. Up to 64 VLANs can have DHCP Snooping
enabled. Note that enabling DHCP Snooping at the switch level is not allowed if it is enabled for one or
more VLANs.
By default, when DHCP Snooping is enabled for a specific VLAN, MAC address verification and Option-
82 data insertion is also enabled for the VLAN by default. To disable or enable either of these two
features, use the ip helper dhcp-snooping vlan command with either the mac-address verification or
option-82 data-insertion parameters. For example:
-> ip helper dhcp-snooping vlan 200 mac-address verification disable
-> ip helper dhcp-snooping vlan 200 option-82 data-insertion disable
Note that if the binding table functionality is enabled, disabling Option-82 data insertion for the VLAN is
not allowed. See “Configuring the DHCP Snooping Binding Table” on page 18-20 for more information.
Note. If DHCP Snooping is not enabled for a VLAN, then all ports associated with the VLAN are consid-
ered trusted ports. VLAN-level DHCP Snooping does not filter DHCP traffic on ports associated with a
VLAN that does not have this feature enabled.
ip helper dhcp-snooping binding
ip helper dhcp-snooping mac-address verification
ip helper dhcp-snooping option-82 data-insertion
Seitenansicht 353
1 2 ... 349 350 351 352 353 354 355 356 357 358 359 ... 701 702

Kommentare zu diesen Handbüchern

Keine Kommentare