210
Task Description
Configuring the network-side port
Configures VLAN and other settings required for many-to-one
VLAN mapping (required).
Configuration prerequisites
Before configuring many-to-one VLAN mapping:
•
Make sure that all home users obtain IP addresses through DHCP. For how to assign IP addresses
through DHCP, see
Layer 3—IP Services Configuration Guide
.
•
Create CVLANs and SVLANs, and plan CVLANs-to-SVLAN mappings.
Enabling DHCP snooping
Step Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enable DHCP snooping.
dhcp-snooping
Disabled by default.
Enabling ARP detection in SVLANs
The ARP detection function enables a switch to modify the VLAN attributes of ARP packets, which is
impossible under the normal ARP packet processing procedure. For more information about ARP
detection, see
Security Configuration Guide
.
To enable ARP detection in all SVLANs:
Step Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enter VLAN view.
vlan
vlan-id
N/A
3.
Enable ARP detection.
arp detection enable
Disabled by default.
NOTE:
To defend against ARP attacks, enable ARP detection also in all CVLANs.
Configuring an uplink policy
To configure an uplink policy to map a group of CVLANs to one SVLAN:
Step Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Create a class and enter class
view.
traffic classifier
tcl-name
operator
or
Repeat these steps to configure one
class for each group of CVLANs.
3.
Configure multiple CVLANs
as match criteria.
if-match customer-vlan-id
{
vlan-list
|
vlan-id1
to
vlan-id2
}