Overview Of Ip Filtering - 3Com WX3000 Series Operation Manual

Unified switches switching engine
Table of Contents

Advertisement

Table 3-1 Ways of handling a DHCP packet with Option 82
Handling
policy
Drop
Keep
Neither of the two
sub-options is
configured
Replace
Circuit ID
sub-option is
configured
Remote ID
sub-option is
configured
When receiving a DHCP client's request without Option 82, the DHCP snooping device will add the
option field with the configured sub-option and then forward the packet. For details, see
Table 3-2 Ways of handling a DHCP packet without Option 82
Sub-option configuration
Neither of the two
sub-options is configured.
Circuit ID sub-option is
configured.
Remote ID sub-option is
configured.
The circuit ID and remote ID sub-options in Option 82, which can be configured simultaneously or
separately, are independent of each other in terms of configuration sequence.
When the DHCP snooping device receives a DHCP response packet from the DHCP server, the DHCP
snooping device will delete the Option 82 field, if contained, before forwarding the packet, or will directly
forward the packet if the packet does not contain the Option 82 field.

Overview of IP Filtering

A denial-of-service (DoS) attack means an attempt of an attacker sending a large number of forged
address requests with different source IP addresses to the server so that the network cannot work
normally. The specific effects are as follows:
Sub-option
configuration
Drop the packet.
Forward the packet without changing Option 82.
Forward the packet after replacing the original Option 82 with
the default content.
The storage format of Option 82 content is the one specified with
the dhcp-snooping information format command or the
default HEX format if this command is not executed.
Forward the packet after replacing the circuit ID sub-option of
the original Option 82 with the configured circuit ID sub-option in
ASCII format.
Forward the packet after replacing the remote ID sub-option of
the original Option 82 with the configured remote ID sub-option
in ASCII format.
Forward the packet after adding Option 82 with the default contents.
The format of Option 82 is the one specified with the
dhcp-snooping information format command or the default HEX
format if this command is not executed.
Forward the packet after adding Option 82 with the configured circuit
ID sub-option in ASCII format.
Forward the packet after adding Option 82 with the configured
remote ID sub-option in ASCII format.
The DHCP snooping device will...
The DHCP snooping device will...
3-4
Table
3-2.

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Wx3024Wx3010Wx3008

Table of Contents