450
•
Enable dynamic IPv4SG on Ten-GigabitEthernet 1/0/1 to filter incoming packets by using the
IPv4SG bindings generated based on DHCP snooping entries. Only packets from the DHCP
client are allowed to pass.
Figure 123 Network diagram
Configuration procedure
1.
Configure the DHCP server.
For information about DHCP server configuration, see
Layer 3—IP Services Configuration
Guide
.
2.
Configure the device:
# Configure IP addresses for the interfaces. (Details not shown.)
# Enable DHCP snooping.
<Device> system-view
[Device] dhcp snooping enable
# Configure Ten-GigabitEthernet 1/0/2 as a trusted interface.
[Device] interface ten-gigabitethernet 1/0/2
[Device-Ten-GigabitEthernet1/0/2] dhcp snooping trust
[Device-Ten-GigabitEthernet1/0/2] quit
# Enable IPv4SG on Ten-GigabitEthernet 1/0/1 and verify the source IP address and MAC
address for dynamic IPSG.
[Device] interface ten-gigabitethernet 1/0/1
[Device-Ten-GigabitEthernet1/0/1] ip verify source ip-address mac-address
# Enable recording of client information in DHCP snooping entries on Ten-GigabitEthernet
1/0/1.
[Device-Ten-GigabitEthernet1/0/1] dhcp snooping binding record
[Device-Ten-GigabitEthernet1/0/1] quit
Verifying the configuration
# Verify that a dynamic IPv4SG binding is generated based on a DHCP snooping entry.
[Device] display ip source binding dhcp-snooping
Total entries found: 1
IP Address MAC Address Interface VLAN Type
192.168.0.1 0001-0203-0406 XGE1/0/1 1 DHCP snooping
Dynamic IPv4SG using DHCP relay agent configuration
example
Network requirements
As shown in
, DHCP relay agent is enabled on the switch. The host obtains an IP address
from the DHCP server through the DHCP relay agent.
Enable dynamic IPv4SG on VLAN-interface 100 to filter incoming packets by using the IPv4SG
bindings generated based on DHCP relay entries.
Содержание FlexFabric 5940 SERIES
Страница 251: ...238 ...