Configuring the ike keepalive function – H3C Technologies H3C S12500-X Series Switches User Manual

Page 226

Advertising
background image

214

519B

Verifying the configuration

# Display dynamic IPv4 source guard binding entries obtained from DHCP snooping.

[Switch] display ip source binding dhcp-snooping

Total entries found: 1

IP Address MAC Address Interface VLAN Type

192.168.0.1 0001-0203-0406 XGE1/0/1 1 DHCP snooping

The output shows that IP source guard has generated a dynamic IPv4 source guard binding entry on
Ten-GigabitEthernet 1/0/1 based on the DHCP snooping entry.

296B

Dynamic IPv4 source guard using DHCP relay configuration
example

520B

Network requirements

As shown in

916H

Figure 66

, the host and the DHCP server are connected to the switch through interfaces

VLAN-interface 100 and VLAN-interface 200 respectively. DHCP relay is enabled on the switch. The host

obtains an IP address from the DHCP server through the DHCP relay agent.
Enable dynamic IPv4 source guard on VLAN-interface 100 to filter received packets based on the DHCP
relay entry generated on the switch.

Figure 66 Network diagram

521B

Configuration procedure

1.

Configure dynamic IPv4 source guard:
# Configure IP addresses for the interfaces. (Details not shown.)
# Enable IPv4 source guard on VLAN-interface 100 to filter packets based on both the source IP
address and the MAC address.

<Switch> system-view

[Switch] interface vlan-interface 100

[Switch-Vlan-interface100] ip verify source ip-address mac-address

[Switch-Vlan-interface100] quit

2.

Configure the DHCP relay agent:
# Enable the DHCP service.

[Switch] dhcp enable

# Enable recording DHCP relay client entries.

[Switch] dhcp relay client-information record

# Configure VLAN-interface 100 to work in DHCP relay mode.

[Switch] interface vlan-interface 100

[Switch-Vlan-interface100] dhcp select relay

# Specify the IP address of the DHCP server.

Advertising