Configuring Dhcp Relay Agent Security Functions - H3C S5600 Series Operation Manual

Hide thumbs Also See for H3C S5600 Series:
Table of Contents

Advertisement

Operation Manual – DHCP
H3C S5600 Series Ethernet Switches
Note:
You can configure up to eight DHCP server IP addresses in a DHCP server group.
You can map multiple VLAN interfaces to one DHCP server group. But one VLAN
interface can be mapped to only one DHCP server group.
If you execute the dhcp-server groupNo command repeatedly, the new
configuration overwrites the previous one.
You need to configure the group number specified in the dhcp-server groupNo
command in VLAN interface view by using the command dhcp-server groupNo ip
ip-address&<1-8> in advance.

3.2.4 Configuring DHCP Relay Agent Security Functions

I. Configuring address checking
After relaying an IP address from the DHCP server to a DHCP client, the DHCP relay
agent can automatically record the client's IP-to-MAC binding and generate a dynamic
address entry. It also supports static bindings, which means you can manually
configure IP-to-MAC bindings on the DHCP relay agent, so that users can access
external network using fixed IP addresses.
The purpose of the address checking function on DHCP relay agent is to prevent
unauthorized users from statically configuring IP addresses to access external
networks. With this function enabled, a DHCP relay agent inhibits a user from
accessing external networks if the IP address configured on the user end and the MAC
address of the user end do not match any entries (including the entries dynamically
tracked by the DHCP relay agent and the manually configured static entries) in the user
address table on the DHCP relay agent.
Follow these steps to configure address checking:
Enter system view
Create a static IP-to-MAC
binding
Enter interface view
Enable the address
checking function
To do...
system-view
dhcp-security static
ip-address mac-address
interface interface-type
interface-number
address-check enable
Chapter 3 DHCP Relay Agent Configuration
Use the command...
3-6
Remarks
Optional
Not created by default.
Required
Disabled by default.

Advertisement

Table of Contents
loading

This manual is also suitable for:

S5600-26cS5600-26c-pwrS5600-26fS5600-50cS5600-50c-pwr

Table of Contents