Figure 4.158Switching > Dhcp Snooping > Base > Interface Configuration - Advantech EKI-9516P-HV User Manual

Eki-9500 series
Table of Contents

Advertisement

Interface Configuration
Use the DHCP Snooping Interface Configuration page to view and configure the
DHCP snooping settings for each interface. The DHCP snooping feature processes
incoming DHCP messages. For DHCPRELEASE and DHCPDECLINE messages,
the feature compares the receive interface and VLAN with the client's interface and
VLAN in the binding database. If the interfaces do not match, the application logs the
event (when logging of invalid packets is enabled) and drops the message. If MAC
address validation is globally enabled, messages that pass the initial validation are
checked to verify that the source MAC address and the DHCP client hardware
address match. Where there is a mismatch, DHCP snooping logs the event (when
logging of invalid packets is enabled) and drops the packet.
To access this page, click Switching > DHCP Snooping > Base > Interface Config-
uration.
Figure 4.158 Switching > DHCP Snooping > Base > Interface Configuration
The following table describes the items in the previous figure.
Item
Interface
Trust State
Log Invalid Packets
EKI-9500 Series User Manual
Description
The interface associated with the rest of the data in the row. When
configuring the settings for one or more interfaces, this field identifies
each interface that is being configured.
The trust state configured on the interface. The trust state is one of the
following:
Disabled: The interface is considered to be untrusted and could
potentially be used to launch a network attack. DHCP server
messages are checked against the bindings database. On
untrusted ports, DHCP snooping enforces the following security
rules:
DHCP packets from a DHCP server (DHCPOFFER, DHC-
PACK, DHCPNAK, DHCPRELEASEQUERY) are dropped.
DHCPRELEASE and DHCPDECLINE messages are
dropped if the MAC address is in the snooping database but
the binding's interface is other than the interface where the
message was received.
DHCP packets are dropped when the source MAC address
does not match the client hardware address if MAC Address
Validation is globally enabled.
Enabled: The interface is considered to be trusted and forwards
DHCP server messages without validation.
The administrative mode of invalid packet logging on the interface.
When enabled, the DHCP snooping feature generates a log message
when an invalid packet is received and dropped by the interface.
154

Advertisement

Table of Contents
loading

Table of Contents