Netgear GS516TP Software Administration Manual - Page 55

Services—DHCP Snooping, DHCP Snooping Global Configuration

Page 55 highlights

GS516TP Gigabit Smart Switches Services-DHCP Snooping DHCP Snooping is a useful feature that provides security by filtering untrusted DHCP messages and by building and maintaining a DHCP snooping binding table. An untrusted message is a message that is received from outside the network or firewall and that can cause traffic attacks within your network. The DHCP snooping binding table contains the MAC address, IP address, lease time, binding type, VLAN number, and interface information that corresponds to each of the local untrusted interfaces of a switch. An untrusted interface is an interface that is configured to receive messages from outside the network or firewall. A trusted interface is an interface that is configured to receive messages only from within the network. DHCP snooping acts like a firewall between untrusted hosts and DHCP servers. It also provides way to differentiate between untrusted interfaces connected to the end user and trusted interfaces connected to the DHCP server or another switch. From the Services menu, you can access features described in the following sections: • DHCP Snooping Global Configuration • DHCP Snooping Interface Configuration • DHCP Snooping Binding Configuration • DHCP Snooping Persistent Configuration DHCP Snooping Global Configuration  To configure DHCP snooping global settings: 1. Select System > Services > DHCP Snooping > Global Configuration. 2. Next to DHCP Snooping Mode, select Enable or Disable to turn the DHCP snooping feature on or off. The factory default is disabled. 3. Next to MAC Address Validation, select Enable or Disable to turn on or off the MAC address validation feature. MAC address validation is enabled by default. 4. Enter the VLAN in the VLAN ID field to enable the DHCP snooping mode. 5. Select Enable or Disable from the DHCP snooping mode list to enable or disable the DHCP snooping feature for entered VLAN. The factory default is disabled. 6. Click APPLY to apply the change to the system.  Configuration changes take effect immediately. DHCP Snooping Interface Configuration Use the DHCP Snooping Interface Configuration screen to view and configure each port as a trusted or untrusted port. Any DHCP responses received on a trusted port are forwarded. If a port is configured as untrusted, any DHCP (or BootP) responses received on that port are discarded. 55

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208

55
GS516TP Gigabit Smart Switches
Services—DHCP Snooping
DHCP Snooping is a useful feature that provides security by filtering untrusted DHCP
messages and by building and maintaining a DHCP snooping binding table. An untrusted
message is a message that is received from outside the network or firewall and that can
cause traffic attacks within your network. The DHCP snooping binding table contains the
MAC address, IP address, lease time, binding type, VLAN number, and interface information
that corresponds to each of the local untrusted interfaces of a switch. An untrusted interface
is an interface that is configured to receive messages from outside the network or firewall. A
trusted interface is an interface that is configured to receive messages only from within the
network.
DHCP snooping acts like a firewall between untrusted hosts and DHCP servers. It also
provides way to differentiate between untrusted interfaces connected to the end user and
trusted interfaces connected to the DHCP server or another switch.
From the Services menu, you can access features described in the following sections:
DHCP Snooping Global Configuration
DHCP Snooping Interface Configuration
DHCP Snooping Binding Configuration
DHCP Snooping Persistent Configuration
DHCP Snooping Global Configuration
To configure DHCP snooping global settings:
1.
Select
System > Services > DHCP Snooping > Global Configuration
.
2.
Next to DHCP Snooping Mode, select Enable or Disable to turn the DHCP snooping feature
on or off. The factory default is disabled.
3.
Next to MAC Address Validation, select Enable or Disable to turn on or off the MAC
address validation feature. MAC address validation is enabled by default.
4.
Enter the VLAN in the VLAN ID field to enable the DHCP snooping mode.
5.
Select Enable or Disable from the DHCP snooping mode list to enable or disable the
DHCP snooping feature for entered VLAN. The factory default is disabled.
6.
Click
APPLY
to apply the change to the system.
Configuration changes take effect immediately.
DHCP Snooping Interface Configuration
Use the DHCP Snooping Interface Configuration screen to view and configure each port as a
trusted or untrusted port. Any DHCP responses received on a trusted port are forwarded. If a
port is configured as untrusted, any DHCP (or BootP) responses received on that port are
discarded.