2-5
To do…
Use the command…
Remarks
Correlate the DHCP server
group with the current interface
dhcp relay server-select
group-id
Required
By default, no interface is
correlated with any DHCP
server group.
z
You can specify up to twenty DHCP server groups on the relay agent and eight DHCP server
addresses for each DHCP server group.
z
The IP addresses of DHCP servers and those of relay agent’s interfaces cannot be on the same
subnet. Otherwise, the client cannot obtain an IP address.
z
A DHCP server group can correlate with one or multiple DHCP relay agent interfaces, while a relay
agent interface can only correlate with one DHCP server group. Using the
dhcp relay
server-select
command repeatedly overwrites the previous configuration. However, if the
specified DHCP server group does not exist, the interface still uses the previous correlation.
z
The
group-id
argument in the
dhcp relay server-select
command was specified by the
dhcp
relay server-group
command.
Configuring the DHCP Relay Agent Security Functions
Creating static bindings and enable IP address check
The DHCP relay agent can dynamically record clients’ IP-to-MAC bindings after clients get IP
addresses. It also supports static bindings, which means you can manually configure IP-to-MAC
bindings on the DHCP relay agent, so that users can access external network using fixed IP addresses.
For avoidance of invalid IP address configuration, you can configure the DHCP relay agent to check
whether a requesting client’s IP and MAC addresses match a binding (both dynamic and static bindings)
on the DHCP relay agent. If not, the client cannot access outside networks via the DHCP relay agent.
Follow these steps to create a static binding and enable IP address check:
To do…
Use the command…
Remarks
Enter system view
system-view
—
Create a static binding
dhcp relay security static
ip-address
mac-address
[
interface interface-type
interface-number
]
Optional
No static binding is created
by default.
Enter interface view
interface
interface-type
interface-number
—
Enable invalid IP
address check
dhcp relay address-check
{
disable
|
enable
}
Required
Disabled by default.
Summary of Contents for S5500-SI Series
Page 161: ...3 10 GigabitEthernet1 0 1 2 MANUAL...
Page 220: ...1 7 Clearing ARP entries from the ARP table may cause communication failures...
Page 331: ...1 7 1 1 ms 1 ms 1 ms 1 1 6 1 2 1 ms 1 ms 1 ms 1 1 4 1 3 1 ms 1 ms 1 ms 1 1 2 2 Trace complete...
Page 493: ...2 8...
Page 1111: ...1 10 Installing patches Installation completed and patches will continue to run after reboot...