Dynamic Ipv4 Source Guard Using Dhcp Snooping Configuration Example - H3C S5830V2 Security Configuration Manual

Hide thumbs Also See for S5830V2:
Table of Contents

Advertisement

<SwitchB> system-view
[SwitchB] interface ten-gigabitEthernet 1/0/2
[SwitchB-Ten-GigabitEthernet1/0/2] ip verify source ip-address mac-address
# On Ten-GigabitEthernet 1/0/2, configure a static IPv4 source guard binding entry to allow only
IP packets with the source MAC address of 0001-0203-0406 and the source IP address of
192.168.0.1 to pass.
[SwitchB-Ten-GigabitEthernet1/0/2] ip source binding ip-address 192.168.0.1
mac-address 0001-0203-0406
[SwitchB-Ten-GigabitEthernet1/0/2] quit
# Enable IPv4 source guard on port Ten-GigabitEthernet 1/0/1.
[SwitchB] interface ten-gigabitEthernet 1/0/1
[SwitchB-Ten-GigabitEthernet1/0/1] ip verify source ip-address mac-address
# On Ten-GigabitEthernet 1/0/1, configure a static IPv4 source guard binding entry to allow only
IP packets with the source MAC address of 0001-0203-0407 and the source IP address of
192.168.0.2 to pass.
[SwitchB-Ten-GigabitEthernet1/0/1] ip source binding ip-address 192.168.0.2
mac-address 0001-0203-0407
[SwitchB-Ten-GigabitEthernet1/0/1] quit
3.
Verify the configuration:
# Display static IPv4 source guard binding entries on Switch A. The output shows that the static
IPv4 source guard binding entries are configured successfully.
<SwitchA> display ip source binding static
Total entries found: 2
IP Address
192.168.0.1
192.168.0.3
# Display static IPv4 source guard binding entries on Switch B. The output shows that the static IPv4
source guard binding entries are configured successfully.
<SwitchB> display ip source binding static
Total entries found: 2
IP Address
192.168.0.1
192.168.0.2
Dynamic IPv4 source guard using DHCP snooping
configuration example
Network requirements
As shown in
device, and obtains an IP address from the DHCP server. The DHCP server is connected to port
Ten-GigabitEthernet 1/0/2 of the switch.
Enable DHCP snooping on the switch, so that the host can obtain an IPv4 address from the valid DHCP
server and the IPv4 address and the MAC address of the host can be recorded in a DHCP snooping
entry.
MAC Address
0001-0203-0405 XGE1/0/2
0001-0203-0406 XGE1/0/1
MAC Address
0001-0203-0406 XGE1/0/2
0001-0203-0407 XGE1/0/1
Figure
65, the host (the DHCP client) is connected to port Ten-GigabitEthernet 1/0/1 of the
Interface
Interface
208
VLAN Type
N/A
Static
N/A
Static
VLAN Type
N/A
Static
N/A
Static

Advertisement

Table of Contents
loading

This manual is also suitable for:

S5820v2

Table of Contents