Checking The Configuration - Huawei Quidway S9300 Configuration Manual

Terabit routing switch
Table of Contents

Advertisement

Quidway S9300 Terabit Routing Switch
Configuration Guide - Security
Context
When MAC address security of DHCP snooping is enabled, packets are processed as follows
for a non-DHCP user:
l
l
MAC addresses of DHCP users in the dynamic binding table can be converted to static MAC
addresses, and packets of these users can be forwarded normally. MAC addresses of static users
in the static binding table cannot be converted to static MAC addresses. Therefore, you need to
configure static MAC addresses for the static users to have the packets forwarded normally.
Procedure
Step 1 Run:
system-view
The system view is displayed.
Step 2 Run:
interface interface-type interface-number
The interface view is displayed.
The interface is a user-side interface.
Step 3 Run:
dhcp snooping sticky-mac
MAC address security of DHCP snooping is enabled on the interface.
By default, MAC address security of DHCP snooping is disabled on the S9300.
The dhcp snooping sticky-mac command takes effect only after DHCP snooping is enabled
globally.
If the dhcp snooping sticky-mac command is run, the interface neither learns the MAC address
of the received IP packet nor forwards or sends the received IP packet. The DHCP messages
received by the interface are sent to the CPU of the main control board, and then a dynamic
binding table is generated. After the dynamic binding table is generated, static MAC addresses
are sent to the corresponding interface. That is, dynamic MAC addresses are converted to static
MAC addresses. The static MAC address entry includes information about the MAC address
and VLAN ID of the user. Subsequently, only the packets whose source MAC address matches
the static MAC address can pass through the interface; otherwise, the packets are discarded.
MAC addresses of static users in the static binding table cannot be converted to static MAC
addresses. You need to configure static MAC addresses for the static users to have the packets
forwarded normally.
----End

3.6.5 Checking the Configuration

Issue 06 (2010–01–08)
If a static MAC address is not configured, the packets are discarded after reaching the
interface where the dhcp snooping sticky-mac command is run.
If a static MAC address is configured, the packets are forwarded normally.
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
3 DHCP Snooping Configuration
3-21

Advertisement

Table of Contents
loading

Table of Contents