Configuring Dhcp Snooping; Dhcp Snooping Functions; Ensuring That Dhcp Clients Obtain Ip Addresses From Authorized Dhcp Servers; Recording Ip-To-Mac Mappings Of Dhcp Clients - HP 6125G Configuration Manual

Layer 3 - ip services configuration guide
Hide thumbs Also See for 6125G:
Table of Contents

Advertisement

Configuring DHCP snooping

The DHCP snooping-enabled device must be either between the DHCP client and relay agent, or
between the DHCP client and server. It does not work if it is between the DHCP relay agent and DHCP
server.

DHCP snooping functions

DHCP snooping can:
Ensure that DHCP clients obtain IP addresses from authorized DHCP servers.
1.
Record IP-to-MAC mappings of DHCP clients.
2.
Ensuring that DHCP clients obtain IP addresses from authorized
DHCP servers
With DHCP snooping, the ports of a switch can be configured as trusted or untrusted to make sure that
clients obtain IP addresses only from authorized DHCP servers.
Trusted—A trusted port forwards DHCP messages normally to ensure the clients get IP addresses
from an authorized DHCP server.
Untrusted—An untrusted port discards received DHCP-ACK and DHCP-OFFER messages to avoid
IP address allocation from any unauthorized server.
Configure ports that connect to authorized DHCP servers or other DHCP snooping devices as trusted,
and configure other ports as untrusted.

Recording IP-to-MAC mappings of DHCP clients

DHCP snooping reads DHCP-REQUEST messages and DHCP-ACK messages from trusted ports to record
DHCP snooping entries. A DHCP snooping entry includes the MAC and IP addresses of the client, the
port that connects to the DHCP client, and the VLAN of the port. Using DHCP snooping entries, DHCP
snooping can implement the following functions:
ARP detection—Whether ARP packets are sent from an authorized client is determined based on
DHCP snooping entries. This feature prevents ARP attacks from unauthorized clients. For more
information, see Security Configuration Guide.
MAC-forced forwarding (MFF)—In automatic mode, after intercepting an ARP request from a client,
the MFF device searches DHCP snooping entries for the corresponding gateway address, and
sends the gateway MAC address to the client. This feature forces the client to send all traffic to the
gateway. The gateway can monitor client traffic to prevent malicious attacks among clients. For
more information, see Security Configuration Guide.
IP source guard—IP source guard uses dynamic binding entries generated by DHCP snooping to
filter packets on a per-port basis. This prevents unauthorized packets from traveling through. For
more information, see Security Configuration Guide.
VLAN mapping—The device replaces service provider VLANs (SVLANs) in packets with customer
VLANs (CVLANs) by searching corresponding DHCP snooping entries for DHCP client information
48

Advertisement

Table of Contents
loading

This manual is also suitable for:

6125 blade switch series

Table of Contents