HP 6125G HP 6125G & 6125G/XG Blade Switches Layer 3 - IP Services Conf - Page 46
Configuring the DHCP relay agent security functions, Configuring address check
View all HP 6125G manuals
Add to My Manuals
Save this manual to your list of manuals |
Page 46 highlights
Configuring the DHCP relay agent security functions Configuring address check Address check can block illegal hosts from accessing external networks. With this feature enabled, the DHCP relay agent can dynamically record clients' IP-to-MAC bindings after they obtain IP addresses through DHCP. This feature also supports static bindings. You can also configure static IP-to-MAC bindings on the DHCP relay agent, so users can access external networks using fixed IP addresses. Upon receiving a packet from a host, the DHCP relay agent checks the source IP and MAC addresses in the packet against the recorded dynamic and static bindings. If no match is found, the DHCP relay agent does not learn the ARP entry of the host, and will not forward any reply to the host, so the host cannot access external networks via the DHCP relay agent. Configuration guidelines Follow these guidelines when you create a static binding and enable address check: • The dhcp relay address-check enable command can be executed only on VLAN interfaces. • Before enabling address check on an interface, you must enable the DHCP service, and enable the DHCP relay agent on the interface. Otherwise, the address check configuration is ineffective. • The dhcp relay address-check enable command only checks IP and MAC addresses but not interfaces. • When using the dhcp relay security static command to bind an interface to a static binding entry, make sure that the interface is configured as a DHCP relay agent. Otherwise, address entry conflicts may occur. Configuration procedure To create a static binding and enable address check: Step 1. Enter system view. 2. Create a static binding. 3. Enter interface view. 4. Enable address check. Command Remarks system-view N/A dhcp relay security static ip-address mac-address [ interface interface-type interface-number ] Optional. No static binding is created by default. interface interface-type interface-number N/A dhcp relay address-check enable Disabled by default. Configuring periodic refresh of dynamic client entries A DHCP client unicasts a DHCP-RELEASE message to the DHCP server to release its IP address. The DHCP relay agent simply conveys the message to the DHCP server and does not remove the IP-to-MAC entry of the client. When this feature is enabled, the DHCP relay agent uses the IP address of a client and the MAC address of the DHCP relay interface to send a DHCP-REQUEST message to the DHCP server at specified intervals. 38