DHCP Snooping role

1.dhcp-snooping main role is to cut off illegal dhcp server, configure the untrusted port.
2. DAI fit the switch to prevent the spread of the virus ARP.
3. Establish and maintain a dhcp-snooping binding table, this table first, through dhcp ack packet ip and mac address generation, and second, you can manually specified. This table is a follow-DAI (dynamic arp inspect) and IPSource Guard base. Both similar technology, this table is determined by ip or mac address is legitimate, to limit the users connected to the network.
4. the illegal DHCP server port by building trust and non-trust port isolation, trusted port forwards DHCP packets normal, after DHCPACK DHCP offer and untrusted server port to receive a response, do deal with loss, no forwarding.

Reproduced in: https: //blog.51cto.com/14217006/2410789

Guess you like

Origin blog.csdn.net/weixin_33859665/article/details/93033726