40-6
z
You can configure up to eight DHCP server IP addresses in a DHCP server group.
You can map multiple VLAN interfaces to one DHCP server group. But one VLAN interface can be
z
If you execute the
dhcp-se
d repeatedly, the ne
tion overwrites
.
z
You need to configure the group number specified in the
dhcp-server groupNo
command in VLAN
using
er grou
> in advance.
z
mapped to only one DHCP server group.
rver groupNo
comman
w configura
the previous one
interface view by
the command
dhcp-serv
pNo
ip
ip-address&
<1-8
Configuring DHCP Relay Agent Security Functions
Configuring address checking
After relaying an IP address from the DHCP server to a DHCP client, the DHCP relay agent can
record the client’s IP-to-MAC binding and generate a dynamic address entry. It also
supports st tic bindings, which means you can manually configure IP-to-MAC bindings on the DHCP
The
from
ction enabled, a
use
dyn
red static entries) in the user
address table on the DHCP relay agent.
ollow these steps to configure address checking:
automatically
a
relay agent, so that users can access external network using fixed IP addresses.
purpose of the address checking function on DHCP relay agent is to prevent unauthorized users
statically configuring IP addresses to access external networks. With this fun
DHCP relay agent inhibits a user from accessing external networks if the IP address configured on the
r end and the MAC address of the user end do not match any entries (including the entries
amically tracked by the DHCP relay agent and the manually configu
F
To do…
Use the command…
Remarks
Enter system view
system-view
—
Create a static
IP-to-MAC binding
dhcp-security static
ip-address
mac
-
address
Optional
Not created by default.
Enter interface view
interface
interface-type
interface-number
—
Enable the address
checking function
address-check enable
Disabled by default.
Required