Enterasys Enterasys SecureStack B2 B2G124-24 Especificaciones Pagina 493

  • Descarga
  • Añadir a mis manuales
  • Imprimir
  • Pagina
    / 600
  • Tabla de contenidos
  • MARCADORES
  • Valorado. / 5. Basado en revisión del cliente
Vista de pagina 492
SecureStack B2 Configuration Guide 18-1
18
DHCP Snooping and
Dynamic ARP Inspection
Thischapterdescribestwosecurityfeatures:
•DHCPsnooping,whichmonitorsDHCPmessagesbetweenaDHCPclientandDHCPserver
tofilterharmfulDHCPmessagesandtobuildadatabaseofauthorizedaddressbindings
DynamicARPinspection,whichusesthebindingsdatabasecreatedbytheDHCPsnooping
featuretorejectinvalidand
maliciousARPpackets
DHCP Snooping Overview
DHCPsnoopingmonitorsDHCPmessagesbetweenDHCPclientsandDHCPserverstofilter
harmfulDHCPmessagesandtobuildabindingsdatabaseof{MACaddress,IPaddress,VLAN
ID,port}tuplesthatareconsideredauthorized.
DHCPsnoopingisdisabledgloballyandonallVLANsbydefault.Portsareuntrustedbydefault.
DHCPsnoopingmustbeenabledgloballyandonspecificVLANs.PortswithintheVLANsmust
beconfiguredastrustedoruntrusted.DHCPserversmustbereachedthroughtrustedports.
DHCPsnoopingenforcesthefollowingsecurityrules:
•DHCPpacketsfromaDHCPserver(DHCPOFFER,DHCPACK,DHCPNAK)aredroppedif
receivedonanuntrustedport.
•DHCPRELEASEandDHCPDECLINEmessagesaredroppediftheyareforaMACaddress
inthesnoopingdatabasebutthebindingʹsinterfaceinthedatabaseisdifferentfromthe
interfacewherethemessagewasreceived.
•Onuntrustedinterfaces,theswitchdropsDHCPpacketswhosesource
MACaddressdoesnot
matchtheclienthardwareaddress.Thisfeatureisaconfigurableoption.
DHCP Message Processing
ThehardwareidentifiesallincomingDHCPpacketsonportswhereDHCPsnoopingisenabled.
Onuntrustedports,thehardwaretrapsallincomingDHCPpacketstotheCPU.Ontrustedports,
For information about... Refer to page...
DHCP Snooping Overview 18-1
DHCP Snooping Commands 18-4
Dynamic ARP Inspection Overview 18-16
Dynamic ARP Inspection Commands 18-20
Vista de pagina 492
1 2 ... 488 489 490 491 492 493 494 495 496 497 498 ... 599 600

Comentarios a estos manuales

Sin comentarios