Technical Reference; Dhcp Snooping Overview - ZyXEL Communications XGS2210-28 User Manual

Xgs2210 series. intelligent layer 2 gbe switch
Table of Contents

Advertisement

The following table describes the labels in this screen.
Table 127 Advanced Application > IP Source Guard > IPv6 DHCP Trust Setup
LABEL
Active
Slot (Stacking
mode)
Port (Standalone
or stacking mode)
*
Trusted state
Apply
Cancel

26.19 Technical Reference

This section provides technical background information on the topics discussed in this chapter.

26.19.1 DHCP Snooping Overview

Use DHCP snooping to filter unauthorized DHCP packets on the network and to build the binding table
dynamically. This can prevent clients from getting IP addresses from unauthorized DHCP servers.
26.19.1.1 Trusted vs. Untrusted Ports
Every port is either a trusted port or an untrusted port for DHCP snooping. This setting is independent of
the trusted/untrusted setting for ARP inspection. You can also specify the maximum number for DHCP
packets that each port (trusted or untrusted) can receive each second.
Trusted ports are connected to DHCP servers or other switches. The Switch discards DHCP packets from
trusted ports only if the rate at which DHCP packets arrive is too high. The Switch learns dynamic
bindings from trusted ports.
Note: If DHCP is enabled and there are no trusted ports, DHCP requests will not succeed.
Chapter 26 IP Source Guard
DESCRIPTION
Select this to specify whether ports are trusted or untrusted ports for DHCP snooping. If you do
not select this then IPv6 DHCP Trust is not used and all ports are automatically trusted.
This field appears only in stacking mode. Click the drop-down list to choose the slot number of
the Switch in a stack.
This field displays the port number. In stacking mode, the first number is the slot ID and the
second is the port number. If you configure the * port, the settings are applied to all of the
ports.
Settings in this row apply to all ports.
Use this row only if you want to make some settings the same for all ports. Use this row first to
set the common settings and then make adjustments on a port-by-port basis.
Note: Changes in this row are copied to all the ports as soon as you make them.
Select whether this port is a trusted port (Trusted) or an untrusted port (Untrusted).
Trusted ports are connected to DHCPv6 servers or other switches.
Untrusted ports are connected to subscribers, and the Switch discards DHCPv6 packets from
untrusted ports in the following situations:
The packet is a DHCPv6 server packet (for example, ADVERTISE, REPLY, or RELAY-REPLY).
The source MAC address and source IP address in the packet do not match any of the
current bindings.
Click Apply to save your changes to the Switch's run-time memory. The Switch loses these
changes if it is turned off or loses power, so use the Save link on the top navigation panel to
save your changes to the non-volatile memory when you are done configuring.
Click this to reset the values in this screen to their last-saved values.
XGS2210 Series User's Guide
293

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents