Configuring Dhcp Snooping; Global Dhcp Snooping Configuration; Figure 101: Dhcp Snooping Configuration; Table 86: Dhcp Snooping Configuration - D-Link DWS-4026 User Manual

Dws-4000 series unified wired & wireless access system
Table of Contents

Advertisement

D-Link Unified Access System
C
DHCP S
ONFIGURING
DHCP snooping is a security feature that monitors DHCP messages between a DHCP client and DHCP servers to filter
harmful DHCP messages and to build a bindings database of {MAC address, IP address, VLAN ID, port} tuples that are
considered authorized. You can enable DHCP snooping globally and on specific VLANs, and configure ports within the
VLAN to be trusted or untrusted. DHCP servers must be reached through trusted ports. DHCP snooping enforces the
following security rules:
DHCP packets from a DHCP server (DHCPOFFER, DHCPACK, DHCPNAK, DHCPRELEASEQUERY) are dropped if
received on an untrusted port.
DHCPRELEASE and DHCPDECLINE messages are dropped if destined for a MAC address in the snooping database,
but the corresponding IP address in the snooping database is different than the interface where the message was
received.
On untrusted interfaces, the switch drops DHCP packets whose source MAC address does not match the client
hardware address. This feature is a configurable option.
The hardware identifies all incoming DHCP packets on ports where DHCP snooping is enabled. DHCP snooping is enabled
on a port if (a) DHCP snooping is enabled globally, and (b) the port is a member of a VLAN where DHCP snooping is
enabled. On untrusted ports, the hardware traps all incoming DHCP packets to the CPU. On trusted ports, the hardware
forwards client messages and copies server messages to the CPU so that DHCP snooping can learn the binding.
G
DHCP S
LOBAL
NOOPING
To access the DHCP Snooping Configuration page, click LAN > L2 Features > DHCP Snooping > Configuration in the
navigation tree.
Field
DHCP Snooping Mode
MAC Address Validation
Click Submit to apply the new configuration and cause the change to take effect. These changes will not be retained
across a power cycle unless a Save configuration is performed.
Page 176

Configuring DHCP Snooping

NOOPING
C
ONFIGURATION

Figure 101: DHCP Snooping Configuration

Table 86: DHCP Snooping Configuration

Description
Enables or disables the DHCP Snooping feature. The default is Disable.
Enables or disables the validation of sender MAC Address for DHCP Snooping. The
default is Enable.
Software User Manual
Document 34CSFP6XXUWS-SWUM100-D7
12/10/09

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Dwl-8600apDws-4000 series

Table of Contents