Configuring Dhcp Relay Agent Security - H3C S7500 Series Operation Manual

Hide thumbs Also See for S7500 Series:
Table of Contents

Advertisement

Operation Manual – DHCP
H3C S7500 Series Ethernet Switches
To enhance reliability, you can set multiple DHCP servers on the same network.
These DHCP servers form a DHCP server group. When the interface establishes
mapping relationship with the DHCP server group, the interface forwards the DHCP
packets to all servers in the server group.
Follow these steps to configure an interface to operate in DHCP relay agent mode:
Enter system view
Configure the DHCP
server IP address(es) in a
specified DHCP server
group
Map an interface to a
DHCP server group
Note:
You can configure up to eight external DHCP IP addresses in a DHCP server
group.
You can map multiple VLAN interfaces to one DHCP server group. But one VLAN
interface can be mapped to only one DHCP server group. If you execute the
dhcp-server groupNo command repeatedly, the new configuration overwrites the
previous one.
You need to configure the group number specified in the dhcp-server groupNo
command in VLAN interface view by using the command dhcp-server groupNo ip
ipaddress-address&<1-8> in advance.

3.2.4 Configuring DHCP Relay Agent Security

I. Configuring address checking
When a DHCP client obtains an IP address from a DHCP server with the help of a
DHCP relay agent, the DHCP relay agent creates an entry (dynamic entry) in the user
address table to track the IP-MAC address binding information about the DHCP client.
You can also configure user address entries manually (static entries) to bind an IP
address and a MAC address statically.
The purpose of the address checking function on DHCP relay agent is to prevent
unauthorized users from statically configuring IP addresses to access external
networks. With this function enabled, a DHCP relay agent inhibits a user from
To do...
system-view
dhcp-server groupNo ip
ip-address&<1-8>
interface interface-type
interface-number
dhcp-server groupNo
Chapter 3 DHCP Relay Agent Configuration
Use the command...
3-5
Remarks
Required
By default, no DHCP
server IP address is
configured in a DHCP
server group
Required
By default, a VLAN
interface is not mapped to
any DHCP server group

Advertisement

Table of Contents
loading

Table of Contents