data:image/s3,"s3://crabby-images/d9ce9/d9ce95c4b64796b521e8f16a7d6d00ce4a183472" alt="H3C S9500E Series Скачать руководство пользователя страница 158"
158
•
On Switch A, create a DHCP snooping entry for Client A.
•
On port GigabitEthernet 3/0/1 of Switch A, enable dynamic binding function to prevent
attackers from using forged IP addresses to attack the server.
For detailed configuration of a DHCP server, see
DHCP
in the
Layer 3 – IP Services Configuration Guide.
Figure 53
Network diagram for configuring dynamic binding function
Configuration procedure
1.
Configure Switch A
Configure dynamic binding function on port GigabitEthernet 3/0/1 to filter packets based on
both the source IP address and MAC address.
<SwitchA> system-view
[SwitchA] interface gigabitethernet 3/0/1
[SwitchA-GigabitEthernet3/0/1] ip check source ip-address mac-address
[SwitchA-GigabitEthernet3/0/1] quit
Enable DHCP snooping.
[SwitchA] dhcp-snooping
Configure the port connecting to the DHCP server as a trusted port.
[SwitchA] interface gigabitethernet 3/0/2
[SwitchA-GigabitEthernet3/0/2] dhcp-snooping trust
[SwitchA-GigabitEthernet3/0/2] quit
2.
Verify the configuration
Display the dynamic binding entries that port GigabitEthernet 3/0/1 has obtained from DHCP
snooping.
[SwitchA] display ip check source
Total entries found: 1
MAC IP Vlan Port Status
0001-0203-0406 192.168.0.1 1 GigabitEthernet3/0/1 DHCP-SNP
Display the dynamic entries of DHCP snooping and check it is identical with the dynamic entries
that port GigabitEthernet 3/0/1 has obtained.
[SwitchA] display dhcp-snooping
DHCP Snooping is enabled.
The client binding table for all untrusted ports.
Type : D--Dynamic , S--Static
Type IP Address MAC Address Lease VLAN Interface
==== =============== ============== ============ ==== =================
D 192.168.0.1 0001-0203-0406 86335 1 GigabitEthernet3/0/1