ZyXEL Communications VPN Series Handbook page 738

Security firewalls
Table of Contents

Advertisement

Disable option 60
Router(config-if-wan1)# no ip address dhcp option-60
Test DHCP Option 60
To test the DHCP option 60 function, use a packet capture software to check if option
60 string exists in the DHCP discover message sent from the ZyWALL/USG WAN port.
What Can Go Wrong?
1
Avoid using the same option 60 string on two or more DHCP servers. It
may cause duplicate DHCP serving confliction.
2
Since packets with option 60 are clear, do not consider it as a secure
way for DHCP server authentication.
www.zyxel.com
738/810

Advertisement

Table of Contents
loading

Table of Contents