Configuring Dhcpv6 Snooping; Overview; Application Of Trusted And Untrusted Ports - HP FlexNetwork MSR2003 Configuration Manual

Flexnetwork msr router series
Hide thumbs Also See for FlexNetwork MSR2003:
Table of Contents

Advertisement

Configuring DHCPv6 snooping

This feature is supported only on the following ports:
Layer 2 Ethernet ports on the following modules:
HMIM-8GSW.
HMIM-24GSW.
HMIM-24GSW-PoE.
SIC-4GSW.
SIC-4GSW-PoE.
Fixed Layer 2 Ethernet ports on MSR2004-24/2004-48 routers.
Fixed Layer 2 Ethernet ports on MSR1002-4/1003-8S routers.

Overview

DHCPv6 snooping works between the DHCPv6 client and server, or between the DHCPv6 client and
DHCPv6 relay agent. It guarantees that DHCPv6 clients obtain IP addresses from authorized
DHCPv6 servers. Also, it records IP-to-MAC bindings of DHCPv6 clients (called DHCPv6 snooping
entries) for security purposes.
DHCPv6 snooping does not work between the DHCPv6 server and DHCPv6 relay agent.
DHCPv6 snooping defines trusted and untrusted ports to make sure that clients obtain IPv6
addresses only from authorized DHCPv6 servers.
Trusted—A trusted port can forward DHCPv6 messages correctly to make sure the clients get
IPv6 addresses from authorized DHCPv6 servers.
Untrusted—An untrusted port discards received messages sent by DHCPv6 servers to
prevent unauthorized servers from assigning IPv6 addresses.
DHCPv6 snooping reads DHCP-ACK messages received from trusted ports and DHCP-REQUEST
messages to create DHCPv6 snooping entries. A DHCPv6 snooping entry includes the MAC and IP
addresses of a client, the port that connects to the DHCPv6 client, and the VLAN. You can use the
display ipv6 dhcp snooping binding command to display the IP addresses of users for
management.

Application of trusted and untrusted ports

Configure ports facing the DHCPv6 server as trusted ports, and configure other ports as untrusted
ports.
As shown in
DHCPv6 server as a trusted port. The trusted port forwards response messages from the DHCPv6
server to the client. The untrusted port connected to the unauthorized DHCPv6 server discards
incoming DHCPv6 response messages.
Figure
110, configure the DHCPv6 snooping device's port that is connected to the
274

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents