3Com 7757 Configuration Manual page 617

3com switch 7750 family
Hide thumbs Also See for 7757:
Table of Contents

Advertisement

Configuring DHCP Relay
Agent Security
Functions
However, if two equal-cost uplinks to the DHCP server exist, the packets from a
client may have different source IP addresses. As a result, some packets may fail to
pass the validity check.
Switch 7750 Ethernet switches supports specifying the source IP address of uplink
packets. With this feature enabled on the relay agent, the source IP address of a
client's packet to be forwarded to the DHCP server is the IP address of the
receiving interface.
Table 488 Specify the source IP address of uplink packets
Operation
Enter system view
Specify the source IP address of
packets on the DHCP relay
agent
Configuring address checking
When a DHCP client obtains an IP address from a DHCP server through the DHCP
relay agent, the DHCP relay agent automatically generates the binding between
the client's IP address, MAC address, VLAN ID, and port number. You can also
manually configure such bindings for clients on the DHCP relay agent.
The purpose of the address checking function on DHCP relay agent is to prevent
unauthorized users from statically configuring IP addresses to access external
networks. With this function enabled, a DHCP relay agent inhibits a user from
accessing external networks if the binding of the IP address, MAC address, VLAN
ID, and port number do not match any entries (including the entries dynamically
tracked by the DHCP relay agent and the manually configured static entries) in the
user address table on the DHCP relay agent.
Table 489 Configure address checking
Operation
Enter system view
Configure a static user
address entry on the DHCP
relay agent
Enter interface view
Enable the address checking
function
Configuring DHCP Relay Agent
Command
system-view
dhcp relay source-ip
source-interface
Command
system-view
dhcp-security static
ip-address mac mac-address
[ vlan vlan-id | port
interface-type
interface-number ]*
interface interface-type
interface-number
address-check enable
617
Description
-
Required
This feature is disabled
by default. That is, the
source IP address of the
packets sent to the
DHCP server is the IP
address of the relay
agent's interface that
connects to the DHCP
server.
Description
-
Optional
By default, no DHCP user
address entry is configured
-
Required
By default, the address
checking function is disabled

Advertisement

Table of Contents
loading

This manual is also suitable for:

775077587754

Table of Contents