Dhcp Snooping; Enabling Dhcp Snooping; Dhcp Trust State - Siemens S223 User Manual

Siemens single-board fast ethernet switch operators user manual
Table of Contents

Advertisement

UMN:CLI
8.8.7
8.8.7.1
!
!
8.8.7.2
i
258

DHCP Snooping

For enhanced security, the hiD 6615 S223/S323 provides the DHCP snooping feature.
The DHCP snooping filters untrusted DHCP messages and maintains a DHCP snooping
binding table. An untrusted message is a message received from outside the network,
and an untrusted interface is an interface configured to receive DHCP messages from
outside the network.
The DHCP snooping basically permits all the trusted messages received from within the
network and filters untrusted messages. In case of untrusted messages, all the binding
entries are recorded in a DHCP snooping binding table. This table contains a hardware
address, IP address, lease time, VLAN ID, interface, etc.
It also gives you a way to differentiate between untrusted interfaces connected to the
end-user and trusted interfaces connected to the DHCP server or another switch.

Enabling DHCP Snooping

To enable the DHCP snooping on the system, use the following command
Command
ip dhcp snooping
no ip dhcp snooping
Upon entering the ip dhcp snooping command, the DHCP_OFFER and DHCP_ACK
messages from all the ports will be discarded before specifying a trusted port.
To enable the DHCP snooping on a VLAN, use the following command
Command
ip dhcp snooping vlan VLANS
no ip dhcp snooping vlan
VLANS
You must enable DHCP snooping on the system before enabling DHCP snooping on a
VLAN.

DHCP Trust State

To define a state of a port as trusted or untrusted, use the following command.
Command
ip dhcp snooping trust PORTS
no ip dhcp snooping trust
PORTS
Note that, the DHCP snooping only sees the DHCP_OFFER and DHCP_ACK messages
which are received from untrusted interfaces.
SURPASS hiD 6615 S223/S323 R1.5
Mode
Enables the DHCP snooping on the system.
Global
Disables the DHCP snooping on the system. (default)
Mode
Enables the DHCP snooping on a specified VLAN.
Global
Disables the DHCP snooping on a specified VLAN.
Mode
Defines a state of a specified port as trusted.
Global
Defines a state of a specified port as untrusted.
User Manual
Description
Description
Description
A50010-Y3-C150-2-7619

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

S323Surpass hid 6615 s223Surpass hid 6615 s323 r1.5

Table of Contents