Enterasys Enterasys SecureStack B2 B2G124-24 Spécifications Page 495

  • Télécharger
  • Ajouter à mon manuel
  • Imprimer
  • Page
    / 600
  • Table des matières
  • MARQUE LIVRES
  • Noté. / 5. Basé sur avis des utilisateurs
Vue de la page 494
DHCP Snooping Overview
SecureStack B2 Configuration Guide 18-3
switchisrebooting,whentheswitchreceivesaDHCPDISCOVERYorREQUESTmessage,the
clientʹsbindingwillgotoatentativebindingstate.
Rate Limiting
ToprotecttheswitchagainstDHCPattackswhenDHCPsnoopingisenabled,thesnooping
applicationenforcesarateli mitforDHCPpacketsreceivedonuntrustedinterfaces.DHCP
snoopingmonitorsthereceiverateoneachinterfaceseparately.Ifthereceiverateexceedsa
configurablelimit,DHCPsnoopingbringsdowntheinterface.Use
thesetportenablecommand
toreenabletheinterface.Boththerateandthe burst intervalcanbeconfigured.
Basic Configuration
Thefollowingconfigurationproceduredoesnotchangethewritedelaytothesnoopingdatabase
oranyofthedefaultrateli mitingvalues.Additionalconfigurationnotesfollowthisprocedure.
Procedure 18-1 Basic Configuration for DHCP Snooping
Step Task Command(s)
1. Enable DHCP snooping globally on the switch. set dhcpsnooping enable
2. Determine where DHCP clients will be
connected and enable DHCP snooping on their
VLANs.
set dhcpsnooping vlan vlan-list
enable
3. Determine which ports will be connected to the
DHCP server and configure them as trusted
ports.
set dhcpsnooping trust port
port-string enable
4. If desired, enable logging of invalid DHCP
messages on specfic ports.
set dhcpsnooping log-invalid port
port-string enable
5. If desired, add static bindings to the database. set dhcpsnooping binding mac-address
vlan vlan-id ipaddr port port-string
Vue de la page 494
1 2 ... 490 491 492 493 494 495 496 497 498 499 500 ... 599 600

Commentaires sur ces manuels

Pas de commentaire