Web Management Guide-R04

Table Of Contents
Chapter 12
| Security Measures
DHCPv6 Snooping
– 377 –
Clear from Flash – Removes all dynamically learned snooping entries from
flash memory.
Web Interface
To display the binding table for DHCP Snooping:
1. Click IP Service, DHCP, Snooping.
2. Select Show Information from the Step list.
3. Use the Store or Clear function if required.
Figure 233: Displaying the Binding Table for DHCP Snooping
DHCPv6 Snooping
The addresses assigned to DHCPv6 clients on insecure ports can be carefully
controlled using the dynamic bindings registered with DHCPv6 Snooping (or using
the static bindings configured with IPv6 Source Guard). DHCPv6 snooping allows a
switch to protect a network from rogue DHCPv6 servers or other devices which
send port-related information to a DHCPv6 server. This information can be useful in
tracking an IP address back to a physical port.
Command Usage
DHCP Snooping Process
Network traffic may be disrupted when malicious DHCPv6 messages are
received from an outside source. DHCPv6 snooping is used to filter DHCPv6
messages received on a unsecure interface from outside the network or fire
wall. When DHCPv6 snooping is enabled globally and enabled on a VLAN
interface, DHCPv6 messages received on an untrusted interface from a device
not listed in the DHCPv6 snooping table will be dropped.