HP 6125XLG R2306-HP 6125XLG Blade Switch Security Configuration Guide - Page 189

User validity check and ARP packet validity check configuration example, Network requirements

Page 189 highlights

User validity check and ARP packet validity check configuration example Network requirements As shown in Figure 63, configure Switch B to perform ARP packet validity check and user validity check based on static IP source guard binding entries and DHCP snooping entries for connected hosts. Figure 63 Network diagram Switch A Gateway DHCP server XGE1/1/7 Vlan-int10 10.1.1.1/24 DHCP snooping XGE1/1/7 Switch B VLAN 10 XGE1/1/5 XGE1/1/6 Host A DHCP client Host B 10.1.1.6 0001-0203-0607 Configuration procedure 1. Add all the interfaces on Switch B to VLAN 10, and configure the IP address of VLAN-interface 10 on Switch A. (Details not shown.) 2. Configure the DHCP server on Switch A, and configure DHCP address pool 0. system-view [SwitchA] dhcp enable [SwitchA] dhcp server ip-pool 0 [SwitchA-dhcp-pool-0] network 10.1.1.0 mask 255.255.255.0 3. Configure Host A (DHCP client) and Host B. (Details not shown.) 4. Configure Switch B: # Enable DHCP snooping. system-view [SwitchB] dhcp snooping enable [SwitchB] interface ten-gigabitethernet 1/1/7 [SwitchB-Ten-GigabitEthernet1/1/7] dhcp snooping trust [SwitchB-Ten-GigabitEthernet1/1/7] quit [SwitchB] interface ten-gigabitethernet 1/1/5 [SwitchB-Ten-GigabitEthernet1/1/5] dhcp snooping binding record [SwitchB-Ten-GigabitEthernet1/1/5] quit # Enable ARP detection for VLAN 10. [SwitchB] vlan 10 180

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276

180
User validity check and ARP packet validity check
configuration example
Network requirements
As shown in
Figure 63
, configure Switch B to perform ARP packet validity check and user validity check
based on static IP source guard binding entries and DHCP snooping entries for connected hosts.
Figure 63
Network diagram
Configuration procedure
1.
Add all the interfaces on Switch B to VLAN 10, and configure the IP address of VLAN-interface 10
on Switch A. (Details not shown.)
2.
Configure the DHCP server on Switch A, and configure DHCP address pool 0.
<SwitchA> system-view
[SwitchA] dhcp enable
[SwitchA] dhcp server ip-pool 0
[SwitchA-dhcp-pool-0] network 10.1.1.0 mask 255.255.255.0
3.
Configure Host A (DHCP client) and Host B. (Details not shown.)
4.
Configure Switch B:
# Enable DHCP snooping.
<SwitchB> system-view
[SwitchB] dhcp snooping enable
[SwitchB] interface ten-gigabitethernet 1/1/7
[SwitchB-Ten-GigabitEthernet1/1/7] dhcp snooping trust
[SwitchB-Ten-GigabitEthernet1/1/7] quit
[SwitchB] interface ten-gigabitethernet 1/1/5
[SwitchB-Ten-GigabitEthernet1/1/5] dhcp snooping binding record
[SwitchB-Ten-GigabitEthernet1/1/5] quit
# Enable ARP detection for VLAN 10.
[SwitchB] vlan 10
Switch A
Switch B
Host A
Host B
XGE1/1/7
Vlan-int10
10.1.1.1/24
Gateway
DHCP server
XGE1/1/5
XGE1/1/7
XGE1/1/6
DHCP client
VLAN 10
DHCP snooping
10.1.1.6
0001-0203-0607