Dynamic Ipv4 Source Guard Using Dhcp Relay - HP 10500 Series Configuration Manual

Security configuration guide
Hide thumbs Also See for 10500 Series:
Table of Contents

Advertisement

Configuration procedure
1.
Configure DHCP snooping:
# Enable DHCP snooping.
<Device> system-view
[Device] dhcp-snooping
# Configure port GigabitEthernet 1/0/2, which is connected to the DHCP server, as a trusted
port.
[Device] interface gigabitethernet 1/0/2
[Device-GigabitEthernet1/0/2] dhcp-snooping trust
[Device-GigabitEthernet1/0/2] quit
2.
Configure the IPv4 source guard function:
# Configure the IPv4 source guard function on port GigabitEthernet 1/0/1 to filter packets based
on both the source IP address and MAC address.
[Device] interface gigabitethernet 1/0/1
[Device-GigabitEthernet1/0/1] ip verify source ip-address mac-address
[Device-GigabitEthernet1/0/1] quit
Verifying the configuration
# Display the IPv4 source guard entries generated on port GigabitEthernet 1/0/1.
[Device] display ip source binding
Total entries found: 1
MAC Address
0001-0203-0406
# Display DHCP snooping entries to see whether they are consistent with the dynamic entries generated
on GigabitEthernet 1/0/1.
[Device] display dhcp-snooping
DHCP Snooping is enabled.
The client binding table for all untrusted ports.
Type : D--Dynamic , S--Static
Type IP Address
==== =============== ============== ============ ==== =================
D
192.168.0.1
The output shows that a dynamic IPv4 source guard entry has been generated based on the DHCP
snooping entry.

Dynamic IPv4 source guard using DHCP relay

Network requirements
As shown in
VLAN-interface 100 and VLAN-interface 200, respectively. DHCP relay is enabled on the switch. The
host (with the MAC address of 0001-0203-0406) obtains an IP address from the DHCP server through
DHCP relay.
Enable the IPv4 source guard function on the switch's VLAN-interface 100 to filter packets based on the
DHCP relay entry, allowing only packets from clients that obtain IP addresses from the DHCP server to
pass.
IP Address
192.168.0.1
MAC Address
0001-0203-0406 86335
Figure
95, the host and the DHCP server are connected to the switch through interfaces
VLAN
Interface
1
GE1/0/1
Lease
VLAN Interface
1
GigabitEthernet1/0/1
246
Type
DHCP-SNP

Advertisement

Table of Contents
loading

Table of Contents