Netgear GS110TP GS108T/ GS110TP Smart Switch Software Administration Manual - Page 72

Services — DHCP Filtering, DHCP Filtering Configuration

Page 72 highlights

GS108T and GS110TP Smart Switch Software Administration Manual Services - DHCP Filtering DHCP Filtering is a useful feature that can be employed as a security measure against unauthorized DHCP servers. A known attack is when an unauthorized DHCP server responds to a client that is requesting an IP address. The server configures the gateway for the client to be equal to the IP address of the server. At that point, the client sends all of its IP traffic destined to other networks to the unauthorized machine. This gives the attacker the possibility of snooping traffic for passwords or employing a man-in-the-middle attack. DHCP Filtering works by allowing the administrator to configure each port as either a trusted port or an untrusted port. The port that has the authorized DHCP server should be configured as a trusted port. Any DHCP responses received on a trusted port are forwarded. All other ports should be configured as untrusted. Any DHCP (or BootP) responses received are discarded. From the Services link, you can access the following pages: • DHCP Filtering Configuration on page 72 • Interface Configuration on page 73 DHCP Filtering Configuration Use the DHCP Filtering Configuration page to enable or disable the DHCP Filtering feature on the switch. To access the DHCP Filter Configuration page, click System Services  DHCP Filtering  Configuration. To configure global DHCP filtering settings: 1. In the Admin Mode field, select Enable or Disable to turn the DHCP Filtering feature on or off. 2. Click Apply to apply the change to the system. The changes take effect immediately. 3. Click Cancel to cancel the configuration on the screen and reset the data on the screen to the latest value of the switch. 72 | Chapter 2: Configuring System Information

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269

72
|
Chapter 2:
Configuring System Information
GS108T and GS110TP Smart Switch Software Administration Manual
Services — DHCP Filtering
DHCP Filtering is a useful feature that can be employed as a security measure against
unauthorized DHCP servers. A known attack is when an unauthorized DHCP server
responds to a client that is requesting an IP address. The server configures the gateway for
the client to be equal to the IP address of the server. At that point, the client sends all of its IP
traffic destined to other networks to the unauthorized machine. This gives the attacker the
possibility of snooping traffic for passwords or employing a man-in-the-middle attack. DHCP
Filtering works by allowing the administrator to configure each port as either a trusted port or
an untrusted port. The port that has the authorized DHCP server should be configured as a
trusted port. Any DHCP responses received on a trusted port are forwarded. All other ports
should be configured as untrusted. Any DHCP (or BootP) responses received are discarded.
From the Services link, you can access the following pages:
DHCP Filtering Configuration
on page
72
Interface Configuration
on page
73
DHCP Filtering Configuration
Use the DHCP Filtering Configuration page to enable or disable the DHCP Filtering feature
on the switch.
To access the DHCP Filter Configuration page, click
System
Services
DHCP Filtering
Configuration
.
To configure global DHCP filtering settings:
1.
In the
Admin Mode
field, select
Enable
or
Disable
to turn the DHCP Filtering feature on
or off.
2.
Click
Apply
to apply the change to the system. The changes take effect immediately.
3.
Click
Cancel
to cancel the configuration on the screen and reset the data on the screen to
the latest value of the switch.