EasyManuals Logo

Enterasys b5 User Manual

Enterasys b5
714 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #509 background imageLoading...
Page #509 background image
DHCP Snooping Overview
Enterasys B5 CLI Reference 17-3
switchisrebooting,whentheswitchreceivesaDHCPDISCOVERYorREQUESTmessage,the
clientʹsbindingwillgotoatentativebindingstate.
Rate Limiting
ToprotecttheswitchagainstDHCPattackswhenDHCPsnoopingisenabled,thesnooping
applicationenforcesarateli mitforDHCPpacketsreceivedonuntrustedinterfaces.DHCP
snoopingmonitorsthereceiverateoneachinterfaceseparately.Ifthereceiverateexceedsa
configurablelimit,DHCPsnoopingbringsdowntheinterface.Use
thesetportenablecommand
toreenabletheinterface.Boththerateandtheburstintervalcanbeconfigured.
Basic Configuration
Thefollowingconfigurationproceduredoesnotchangethewritedelaytothesnoopingdatabase
oranyofthedefaultrateli mitingvalues.Additionalconfigurationnotesfollowthisprocedure.
Configuration Notes
DHCP Server
•Whentheswitchisoperatinginswitchmode,thentheDHCPserverandDHCPclientsmust
beinthesameVLAN.
•Iftheswitchisinroutingmode(onthoseplatformsthatsupportrouting),thentheDCHP
servercanberemotelyconnectedtoaroutinginterface,orrunninglocally.
•IftheDHCP
serverisremotelyconnected,thentheuseof anIPhelperaddressisrequiredand
MACaddressverificationshouldbedisabled(setdhcpsnoopingverifymacaddress
disable).
•TheDHCPservermustuseScopesinordertoprovidetheIPaddressesperVLAN.
•DHCPsnoopingmustbeenabledontheint erfaces
wheretheDHCPclientsareconnected,
andtheinterfacesmustbeuntrustedDHCPsnoopingports.
•TheroutinginterfacethatisconnectedtotheDHCPservermustbeenabledforDHCP
snoopingandmustbeatrustedDHCPsnoopingport.
Procedure 17-1 Basic Configuration for DHCP Snooping
Step Task Command(s)
1. Enable DHCP snooping globally on the switch. set dhcpsnooping enable
2. Determine where DHCP clients will be
connected and enable DHCP snooping on their
VLANs.
set dhcpsnooping vlan vlan-list
enable
3. Determine which ports will be connected to the
DHCP server and configure them as trusted
ports.
set dhcpsnooping trust port
port-string enable
4. If desired, enable logging of invalid DHCP
messages on specfic ports.
set dhcpsnooping log-invalid port
port-string enable
5. If desired, add static bindings to the database. set dhcpsnooping binding mac-address
vlan vlan-id ipaddr port port-string

Table of Contents

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the Enterasys b5 and is the answer not in the manual?

Enterasys b5 Specifications

General IconGeneral
BrandEnterasys
Modelb5
CategoryOther
LanguageEnglish