DHCP Snooping Configuration Example
635
■
Enable DHCP snooping on the switch, and specify Ethernet 2/0/1 as the DHCP
snooping trusted port.
■
Enable IP filtering on Ethernet 2/0/2, Ethernet 2/0/3, and Ethernet 2/0/4 to
prevent attacks to the server from clients using fake source IP addresses.
■
Create static binding entries on the switch, so that Host A using a fixed IP
address can access external networks.
Network diagram
Figure 165
Network diagram for IP filtering configuration
Configuration procedure
# Enable DHCP snooping on the switch.
<Switch> system-view
[Switch] dhcp-snooping
# Specify Ethernet 2/0/1 as the trusted port.
[Switch] interface Ethernet2/0/1
[Switch-Ethernet2/0/1] dhcp-snooping trust
[Switch-Ethernet2/0/1] quit
# Enable IP filtering on Ethernet 2/0/2, Ethernet 2/0/3, and Ethernet 2/0/4 to filter
packets based on the source IP addresses/MAC addresses.
[Switch] interface Ethernet2/0/2
[Switch-Ethernet2/0/2] ip check source ip-address mac-address
[Switch-Ethernet2/0/2] quit
[Switch] interface Ethernet2/0/3
[Switch-Ethernet2/0/3] ip check source ip-address mac-address
[Switch-Ethernet2/0/3] quit
[Switch] interface Ethernet2/0/4
[Switch-Ethernet2/0/4] ip check source ip-address mac-address
[Switch-Ethernet2/0/4] quit
# Create static binding entries on Ethernet 2/0/2 of the switch.
Switch
DHCP-Snooping
Host A
IP:1.1.1 .1
MAC:0001 -0001- 0001
Eth2/0 /2
Client C
Eth2/0/4
Eth2/0/1
DHCP Server
Client B
Eth2/0/3
Summary of Contents for Switch 7754
Page 32: ...32 CHAPTER 1 CLI OVERVIEW ...
Page 70: ...70 CHAPTER 5 LOGGING IN USING MODEM ...
Page 76: ...76 CHAPTER 7 LOGGING IN THROUGH NMS ...
Page 86: ...86 CHAPTER 9 CONFIGURATION FILE MANAGEMENT ...
Page 120: ...120 CHAPTER 13 ISOLATE USER VLAN CONFIGURATION ...
Page 126: ...126 CHAPTER 14 SUPER VLAN ...
Page 136: ...136 CHAPTER 16 IP PERFORMANCE CONFIGURATION ...
Page 152: ...152 CHAPTER 17 IPX CONFIGURATION ...
Page 164: ...164 CHAPTER 19 QINQ CONFIGURATION ...
Page 172: ...172 CHAPTER 21 SHARED VLAN CONFIGURATION ...
Page 182: ...182 CHAPTER 22 PORT BASIC CONFIGURATION ...
Page 198: ...198 CHAPTER 24 PORT ISOLATION CONFIGURATION ...
Page 208: ...208 CHAPTER 25 PORT SECURITY CONFIGURATION ...
Page 224: ...224 CHAPTER 27 DLDP CONFIGURATION ...
Page 232: ...232 CHAPTER 28 MAC ADDRESS TABLE MANAGEMENT ...
Page 240: ...240 CHAPTER 29 CENTRALIZED MAC ADDRESS AUTHENTICATION CONFIGURATION ...
Page 280: ...280 CHAPTER 30 MSTP CONFIGURATION ...
Page 348: ...348 CHAPTER 35 IS IS CONFIGURATION ...
Page 408: ...408 CHAPTER 39 802 1X CONFIGURATION ...
Page 412: ...412 CHAPTER 40 HABP CONFIGURATION ...
Page 422: ...422 CHAPTER 41 MULTICAST OVERVIEW ...
Page 426: ...426 CHAPTER 42 GMRP CONFIGURATION ...
Page 480: ...480 CHAPTER 47 PIM CONFIGURATION ...
Page 506: ...506 CHAPTER 48 MSDP CONFIGURATION ...
Page 552: ...552 CHAPTER 51 TRAFFIC ACCOUNTING CONFIGURATION ...
Page 570: ...570 CHAPTER 53 HA CONFIGURATION ...
Page 582: ...582 CHAPTER 54 ARP CONFIGURATION SwitchA arp protective down recover interval 200 ...
Page 622: ...622 CHAPTER 58 DHCP RELAY AGENT CONFIGURATION ...
Page 684: ...684 CHAPTER 61 QOS CONFIGURATION ...
Page 718: ...718 CHAPTER 63 CLUSTER ...
Page 738: ...738 CHAPTER 67 UDP HELPER CONFIGURATION ...
Page 752: ...752 CHAPTER 69 RMON CONFIGURATION ...
Page 772: ...772 CHAPTER 70 NTP CONFIGURATION ...
Page 796: ...796 CHAPTER 72 FILE SYSTEM MANAGEMENT ...
Page 802: ...802 CHAPTER 73 BIMS CONFIGURATION ...
Page 814: ...814 CHAPTER 74 FTP AND TFTP CONFIGURATION ...
Page 830: ...830 CHAPTER 75 INFORMATION CENTER ...
Page 836: ...836 CHAPTER 76 DNS CONFIGURATION ...
Page 852: ...852 CHAPTER 77 BOOTROM AND HOST SOFTWARE LOADING ...
Page 858: ...858 CHAPTER 78 BASIC SYSTEM CONFIGURATION DEBUGGING ...