41-10
z
For details about 802.1x authentication, refer to
802.1x and System Guard Operation
.
ended to configure IP filtering on the ports of an aggregation group.
ings. If an ACL fails to be assigned to a binding, the
, the IP addresses of 802.1x clients cannot be obtained. To ensure IP
ts can be updated for corresponding IP-to-MAC entries, you are
recommended to enable 802.1x authentication handshake function; otherwise, you need to
g and forwarding of
ed with the
mac-address
keyword specified on a
t must be specified; otherwise, the packets sent from this IP
the dynamic DHCP snooping entry that has the same IP
. That is, if the static entry is configured after the dynamic entry is
the dynamic entry; if the static entry is configured before
client can obtain the IP address of the static entry, that is,
ot be generated.
figured on a port is the VLAN ID of the port.
z
You are not recomm
z
Enable DHCP snooping and specify trusted ports on the switch before configuring IP filtering
based on the DHCP-snooping table.
z
To implement IP filtering based on IP-to-MAC bindings of authenticated 802.1x clients, the device
assigns an ACL to each of such bind
corresponding authenticated 802.1x client is forced to go offline.
z
IP filtering based on IP-to-MAC bindings of authenticated 802.1x clients requires to be associated
with 802.1x based on MAC address authentication, and requires 802.1x clients to provide IP
addresses; otherwise
addresses of DHCP clien
disable 802.1x authentication triggered by DHCP, ensuring normal receivin
multicast authentication packets.
z
To create a static binding after IP filtering is enabl
port, the
mac-address
argumen
address cannot pass the IP filtering.
z
A static entry has a higher priority than
address as the static one
recorded, the static entry overwrites
DHCP snooping is enabled, no DHCP
the dynamic DHCP snooping entry cann
z
The VLAN ID of the IP static binding con
Displaying and Maintaining DHCP Snooping Configuration
To do…
Use the command…
Remarks
Display the user IP-to-MAC address
mapping entries recorded by the DHCP
display dhcp-snooping
[
unit unit-id
]
snooping function
Display the (enabled/disabled) state of
isplay dhcp-snooping trust
the DHCP snooping function and the
trusted ports
d
Display the IP static binding table
displa
vlan-id
y ip source static binding
[
vlan
|
interface interface-type
interface-number
]
Available in
any view
Remove DHCP snooping entries
reset dhcp-snooping
[
ip-address
]
Available in
user view