Dynamic Ipv4 Source Guard Binding By Dhcp Relay Configuration Example - HP A5830 Series Configuration Manual

Security switch
Hide thumbs Also See for A5830 Series:
Table of Contents

Advertisement

Configuration procedure
Configure DHCP snooping.
1.
# Enable DHCP snooping.
<Device> system-view
[Device] dhcp-snooping
# Configure port GigabitEthernet 1/0/2, which is connected to the DHCP server, as a trusted port.
[Device] interface gigabitethernet1/0/2
[Device-GigabitEthernet1/0/2] dhcp-snooping trust
[Device-GigabitEthernet1/0/2] quit
Configure the IPv4 source guard function.
2.
# Configure the IPv4 source guard function on port GigabitEthernet 1/0/1 to filter packets based on
both the source IP address and MAC address.
[Device] interface gigabitethernet1/0/1
[Device-GigabitEthernet1/0/1] ip verify source ip-address mac-address
[Device-GigabitEthernet1/0/1] quit
Verification
# Display the IPv4 source guard binding entries generated on port GigabitEthernet 1/0/1.
[Device] display ip source binding
Total entries found: 1
MAC Address
0001-0203-0406
# Display DHCP snooping entries to see whether they are consistent with the dynamic entries generated
on GigabitEthernet 1/0/1.
[Device] display dhcp-snooping
DHCP Snooping is enabled.
The client binding table for all untrusted ports.
Type : D--Dynamic , S--Static , R--Recovering
Type IP Address
==== =============== ============== ============ ==== ===== =================
D
192.168.0.1
---
1 dhcp-snooping item(s) found
The output shows that a dynamic IPv4 source guard entry has been generated based on the DHCP
snooping entry.
Dynamic IPv4 source guard binding by DHCP relay
configuration example
Network requirements
As shown in
VLAN-interface 100 and VLAN-interface 200, respectively. DHCP relay is enabled on the switch. The
host (with the MAC address of 0001-0203-0406) obtains an IP address from the DHCP server through
the DHCP relay agent.
IP Address
192.168.0.1
MAC Address
0001-0203-0406 86335
Figure
69, the host and the DHCP server are connected to the switch through interfaces
VLAN
Interface
1
GE1/0/1
Lease
VLAN SVLAN Interface
1
N/A
---
217
Type
DHCP-SNP
GigabitEthernet1/0/1

Advertisement

Table of Contents
loading

Table of Contents