Configuration of address check by using DHCP relay on S3600

关键词:
功能需求

Configuration of address check by using DHCP Relay on S3600

1 Network Requirement

1.1 Enable validation check of user address under VLAN interface, utilize configuration of secure address table, enable legal fix IP address user in VLAN configured DHCP relay to pass address validation check of DHCP security feature by configuring secure address table of DHCP relay.

1.2 SwitchA run as DHCP server, enable DHCP relay feature and address-check feature on SwitchB, MAC address of PC2 is 0015-c50d-20cf, manually configure IP address 192.168.1.3 for PC2

 

2 Network Diagram

 

3 Configuration Procedures

3.1 Enable DHCP function globally

[Switch]dhcp enable

3.2 Specify DHCP Server IP address of DHCP group 1

[Switch]dhcp-server 1 ip 192.168.0.1

3.3 Configure VLAN2 interface address to connect DHCP server

[Switch]vlan 2

[Switch-vlan2]port e1/0/2

[Switch]int vlan 2

[Switch-Vlan-interface2]ip address 192.168.0.2 255.255.255.0

3.4 Configure VLAN3 interface address to connect PCs

[Switch]vlan 3

[Switch-vlan3]port e1/0/3 to e1/0/4

[Switch]int vlan 3

[Switch-Vlan-interface3]ip address 192.168.1.1 255.255.255.0

3.5 Enable DHCP relay function in selected VLAN interface

[Switch-Vlan-interface3] dhcp select relay

3.6 Put VLAN3 interface into DHCP Server group1

[Switch-Vlan-interface3] dhcp-server 1

3.7 Enable address-check feature on switch. PC2 (192.168.1.3) configured manually will not be able to access network.

[Switch-Vlan-interface3]dhcp relay security address-check enable

3.8 Add PC2 into security table

[Switch]dhcp relay security 192.168.1.3 0015-c50d-20cf static

Then PC2 can access network

 

4. Configuration Tips

4.1 During the process of PC obtaining DHCP IP address, switch working as DHCP Relay agent will record MAC address of client, and create a dynamic item of DHCP Relay Security table. therefore, you can prevent client without dynamically allocated IP address from accessing network by utilizing DHCP Relay Security. Of course, you can create static address bundle with IP address and mac-address of client into security table. Like this, this client is also can access this network.

4.2 Ensure the whole network is reachable during configuration.

 

*NOTICE: This case is also applicable to H3C S5600 series switch, Quidway S3500 / S3900 / S5600 / S3526 series switch.

案例信息

案例类型:典型配置
案例号:KMS - 10583
创建时间:2007年4月12日
更新时间:2007年5月11日
发布时间:2007/5/11 3:33:58
文章密级:游客可见
有效期:长期有效
发布者:陈玉龙 [c04979]
点击次数:444
评论平均得分:0
关键词:
产品线:低端交换机
产品系列:
产品版本:
技术分类:网络层协议 IPSec

常用操作
收藏