Configuring Dhcp Snooping Basic Functions; Displaying And Maintaining Dhcp Snooping; Dhcp Snooping Configuration Example - 3Com MSR 50 Series Configuration Manual

3com msr 30-16: software guide
Hide thumbs Also See for MSR 50 Series:
Table of Contents

Advertisement

602
C
36: DHCP S
HAPTER
Configuring DHCP
Snooping Basic
Functions
Displaying and
Maintaining DHCP
Snooping
DHCP Snooping
Configuration
Example
C
NOOPING
ONFIGURATION
Ensuring DHCP clients to obtain IP addresses from valid DHCP servers
If there is an unauthorized DHCP server on a network, the DHCP clients may
obtain invalid IP addresses. With DHCP snooping, the ports of a device can be
configured as trusted or untrusted, ensuring the clients to obtain IP addresses from
authorized DHCP servers.
Trusted: A trusted port is connected to a valid DHCP server directly or indirectly.
It forwards DHCP messages normally, guaranteeing that DHCP clients can
obtain valid IP addresses.
Untrusted: An untrusted port is connected to an invalid DHCP server. The
DHCP-ACK or DHCP-OFFER packets received from the port are discarded,
preventing DHCP clients from receiving invalid IP addresses.
Follow these steps to configure DHCP snooping basic functions:
To do...
Enter system view
Enable DHCP snooping
Enter Ethernet interface view
Specify the port as trusted
n
You must specify the ports connected to the valid DHCP servers as trusted to
ensure that DHCP clients can obtain valid IP addresses. The trusted port and the
port connected to the DHCP client must be in the same VLAN.
To do...
Display DHCP snooping address
binding information
Display information about trusted
ports
Clear DHCP snooping address
binding information
Network requirements
Switch B is connected to a DHCP server through Ethernet1/1, and to two DHCP
clients through Ethernet1/2 and Ethernet1/3.
Ethernet1/1 forwards DHCP server responses while the other two do not.
Switch B records clients' IP-to-MAC address bindings in DHCP-REQUEST
messages and DHCP-ACK messages received from trusted ports.
Use the command...
system-view
dhcp-snooping
interface interface-type
interface-number
dhcp-snooping trust
Use the command...
display dhcp-snooping
display dhcp-snooping trust
reset dhcp-snooping { all | ip
ip-address }
Remarks
-
Required
Disabled by default.
-
Required
Untrusted by default.
Remarks
Available in any view
Available in user view

Hide quick links:

Advertisement

Table of Contents

Troubleshooting

loading

Table of Contents