Restricting The Dhcp Response For A Specific Server - Cisco WS-C6506 Software Manual

Catalyst 6500 series switch
Hide thumbs Also See for WS-C6506:
Table of Contents

Advertisement

Chapter 15
Configuring Access Control
To redirect the broadcast traffic to a specific server port, perform this task in privileged mode (TCP
port 5000 is the intended server application port):
Task
Step 1
Redirect the broadcast packets.
Step 2
Permit all other traffic.
Step 3
Commit the VACL.
Step 4
Map the VACL to VLAN 10.
Note
You could apply the same concept to direct the broadcast traffic to a multicast destination by redirecting
the traffic to a group of ports (see
Figure 15-5
Host A

Restricting the DHCP Response for a Specific Server

When the Dynamic Host Configuration Protocol (DHCP) requests are broadcast, they reach every DHCP
server in the VLAN and multiple responses are returned. With the VACLs, you can restrict the response
from a specific DHCP server and drop the other responses.
OL-8978-04
Command
set security acl ip SERVER redirect 4/1 tcp any host
255.255.255.255 eq 5000
set security acl ip SERVER permit ip any any
commit security acl SERVER
set security acl map SERVER 10
Figure
Redirecting Broadcast Traffic to a Specific Server Port
VACL
Catalyst 6500 series switches
with PFC
VLAN 10
Application broadcast packet
Catalyst 6500 Series Switch Software Configuration Guide—Release 8.7
15-5).
Target
server
4/1
Host B
Host C
Using VACLs in Your Network
15-27

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Catalyst 6506Catalyst 6509Catalyst 6513

Table of Contents