104
•
Record the client IP-MAC binding information in DHCP-REQUEST packets and in DHCP-ACK
packets received by GigabitEthernet 1/0/1.
•
Save the bindings to the FTP server.
Figure 24 Network diagram
Configuration procedure
1.
Configure the DHCP server. (Details not shown.)
2.
Configure the FTP server:
Enable the FTP service, and configure the login username and password. (Details not shown.)
3.
Configure the DHCP snooping device:
a.
From the navigation tree, select
Network
>
Links
>
DHCP Snooping
.
b.
Perform the following tasks:
−
Enable the DHCP snooping feature.
−
Configure GigabitEthernet 1/0/1, the interface that connects to the authorized DHCP
server, as the trusted port.
−
Configure GigabitEthernet 1/0/2, the interface that connects to the client, to record
DHCP snooping entries.
4.
Access the advanced settings page to perform the following tasks:
−
Save the DHCP snooping entries to a remote server.
−
Specify the URL as
ftp://10.1.1.1/database.dhcp
.
−
Specify the username and password for logging into the remote server.
Verifying the configuration
1.
Verify that the DHCP client can obtain an IP address and configuration parameters only from
the authorized DHCP server. (Details not shown.)
2.
Verify that the DHCP snooping device records the snooping entries. (Details not shown.)
3.
Verify that the DHCP database file on the FTP server saves the DHCP snooping entries.
(Details not shown.)
Static ARP entry configuration example
Network requirements
, configure a static ARP entry for the device on the switch. The static ARP
entry prevents spoofing attacks to modify the IP-MAC mapping of the device.