[SwitchB-vlan10] interface gigabitethernet 1/0/3
[SwitchB-GigabitEthernet1/0/3] arp detection trust
[SwitchB-GigabitEthernet1/0/3] quit
After the configurations are completed, ARP packets received on interfaces GigabitEthernet
1/0/1 and GigabitEthernet 1/0/2 are checked against 802.1X entries.
User validity check and ARP packet validity check
configuration example
Network requirements
As shown in
•
Configure the DHCP server on Switch A.
Configure DHCP snooping on Switch B.
•
•
Configure a static IP source guard binding entry for Host B on Switch B.
Enable ARP detection and ARP packet validity check in VLAN 10.
•
Figure 101 Network diagram
Configuration procedure
Add all the ports on Switch B to VLAN 10, and configure the IP address of VLAN-interface 10 on
1.
Switch A. (Details not shown.)
2.
Enable DHCP on Switch A, and configure DHCP address pool 0.
<SwitchA> system-view
[SwitchA] dhcp enable
[SwitchA] dhcp server ip-pool 0
[SwitchA-dhcp-pool-0] network 10.1.1.0 mask 255.255.255.0
3.
Configure the DHCP client on Host A and Host B. (Details not shown.)
4.
Configure Switch B:
# Enable DHCP snooping.
<SwitchB> system-view
Figure
101,
261