Enabling Dhcpv6 Snooping; Configuring A Dhcpv6 Snooping Trusted Port - HP A5120 EI Series Configuration Manual

Hide thumbs Also See for A5120 EI Series:
Table of Contents

Advertisement

they do not forward reply messages from unauthorized DHCPv6 servers. This ensures that the DHCPv6
client can obtain an IPv6 address from the authorized DHCPv6 server only.
As shown in
ports as untrusted.
Recording IP-to-MAC mappings of DHCPv6 clients
DHCPv6 snooping reads DHCPv6 messages to create and update DHCPv6 snooping entries, including
MAC addresses of clients, IPv6 addresses obtained by the clients, ports that connect to DHCPv6 clients,
and VLANs to which the ports belong. You can use the display ipv6 dhcp snooping user-binding
command to view the IPv6 address obtained by each client, so you can manage and monitor the clients'
IPv6 addresses.

Enabling DHCPv6 snooping

To allow clients to obtain IPv6 addresses from an authorized DHCPv6 server, enable DHCPv6 snooping
globally and configure trusted and untrusted ports properly. To record DHCPv6 snooping entries for a
VLAN, enable DHCPv6 snooping for the VLAN.
Follow these steps to enable DHCPv6 snooping:
To do...
Enter system view
Enable DHCPv6 snooping globally
Enter VLAN view
Enable DHCPv6 snooping for the
VLAN

Configuring a DHCPv6 snooping trusted port

After enabling DHCPv6 snooping globally, you can specify trusted and untrusted ports for a VLAN as
needed. A DHCPv6 snooping trusted port forwards DHCPv6 packets. A DHCPv6 snooping untrusted port
discards any DHCPv6 reply message received from a DHCPv6 server. Upon receiving a DHCPv6 request
from a client in the VLAN, the DHCPv6 snooping switch forwards the packet through trusted ports rather
than any untrusted port in the VLAN, reducing network traffic.
Follow these steps to configure a DHCPv6 snooping trusted port:
To do...
Enter system view
Enter interface view
Configure the port as trusted
Figure
70, configure the port that connects to the DHCPv6 server as a trusted port, and other
Use the command...
system-view
interface interface-type interface-
number
ipv6 dhcp snooping trust
Use the command...
system-view
ipv6 dhcp snooping enable
vlan vlan-id
ipv6 dhcp snooping vlan enable
163
Remarks
Required
Disabled by default.
Optional
Disabled by default.
Remarks
Required
By default, all ports of the device
with DHCPv6 snooping globally
enabled are untrusted.

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents