beautypg.com

How dhcpv6 snooping works, Dhcpv6 binding database – Brocade FastIron Ethernet Switch Security Configuration Guide User Manual

Page 356

background image

How DHCPv6 snooping works

When enabled on a VLAN, DHCPv6 snooping stands between untrusted ports (those connected to
host ports) and trusted ports (those connected to DHCPv6 servers). A VLAN with DHCPv6 snooping
enabled forwards DHCPv6 request packets from clients and discards DHCPv6 server reply packets on
untrusted ports, and it forwards DHCPv6 server reply packets on trusted ports to DHCPv6 clients, as
shown in the following figures

FIGURE 31 DHCPv6 snooping at work - on an untrusted port

FIGURE 32 DHCPv6 snooping at work - on a trusted port

DHCPv6 binding database

On trusted ports, DHCPv6 server reply packets are forwarded to DHCPv6 clients. The lease time will
be refreshed when the client renews its IPv6 address with the DHCPv6 server; otherwise the Brocade
device removes the entry when the lease time expires.

How DHCPv6 snooping works

356

FastIron Ethernet Switch Security Configuration Guide

53-1003088-03