Configuring DHCP Snooping on NETGEAR Manage Switches
點擊 - 10762  |  1 個人喜歡這篇文章和覺得有幫助 KBA-96

NETGEAR - Switches  


Configuring DHCP Snooping on NETGEAR Manage Switches

The steps below is based on an actual network setup that I setup inside our laboratory to replicate DHCP snooping. I use NETGEAR UTM150 router to act as my main DHCP server while NETGEAR WNDR3700 is the Rouge DHCP server. GS752TXS is our layer 2 switch.

This is my network setup for replication:

http://i104.photobucket.com/albums/m187/rukawarei/DHCP%20Snooping/image001.png

NETGEAR UTM150 LAN Setup

Created a VLAN 10 profile to a DHCP server for VLAN 10 in GS752TXS.

http://i104.photobucket.com/albums/m187/rukawarei/DHCP%20Snooping/image003.png

GS752TXS VLAN configuration

VLAN 1 – Default

http://i104.photobucket.com/albums/m187/rukawarei/DHCP%20Snooping/image005.png

VLAN10 - Created VLAN 10 and set ports 15-20 as untagged members with a
PVID 10. Port 25 is a Tagged Member

http://i104.photobucket.com/albums/m187/rukawarei/DHCP%20Snooping/image007.png

How to configure DHCP Snooping

1. Go to System > Services > Global Configuration and enable DHCP Snooping mode.

Then apply to save the settings.

http://i104.photobucket.com/albums/m187/rukawarei/DHCP%20Snooping/image009.png

2. Go to the interface where the non-rouge DHCP server is connected. Basically, this will be the trusted interface for DHCP service.

Select the interface and enable Trust mode. Then click Apply to save the settings.

http://i104.photobucket.com/albums/m187/rukawarei/DHCP%20Snooping/image011.png

3. Go the computer connected to VLAN 10 and release/renew the IP address.

The IP address that I got was 10.169.1.2 which is the IP address from the correct DHCP server.

http://i104.photobucket.com/albums/m187/rukawarei/DHCP%20Snooping/image013.png

4. Go to Binding configuration and check the Dynamic Binding Configuration.

Dynamic Binding Configuration shows the IP address of the computer connected to VLAN 10 including its MAC address and VLAN ID.

http://i104.photobucket.com/albums/m187/rukawarei/DHCP%20Snooping/image015.jpg

Test if DHCP snooping is working

1. Disconnect the Trusted DHCP server.

2. On the computer connected to VLAN 10, release/renew the IP address. This is what I got after renewing the IP address:

http://i104.photobucket.com/albums/m187/rukawarei/DHCP%20Snooping/image016.png

As you noticed, even if there is a DHCP server connected to VLAN10, the computer was not able to get an IP address because the port where the rouge DHCP server is not trusted. The only trusted port for DHCP service is port 25.

3. Connect the DHCP server back to port 25 and do release/renew the IP address. The computer connected to VLAN 10 should be able to get an IP address from the trusted DHCP server.

http://i104.photobucket.com/albums/m187/rukawarei/DHCP%20Snooping/image018.png

 

 

    更新日期: 5/24/2015 6:24:05 PM  
 
 

類似的文章

Share this article

 

標籤


Winco (Pacific) Limited      Phone: 3619-8822   Email: support@winco.com.hk