7-7
To do…
Use the command…
Remarks
Enable periodic refresh of
dynamic client entries
dhcp relay security refresh
enable
Optional
Enabled by default.
Configure the refresh interval
dhcp relay security tracker
{
interval
|
auto
}
Optional
auto
by default. (
auto
interval is calculated
by the relay agent according to the number
of client entries.)
Enabling the detection of unauthorized DHCP servers
Unauthorized DHCP servers reply to DHCP clients with incorrect IP addresses.
With this feature enabled, upon receiving a DHCP request, the DHCP relay agent will record the IP
address of the DHCP server which assigned an IP address to the DHCP client and the receiving
interface. The administrator can use this information to check out any DHCP unauthorized servers.
Follow these steps to enable unauthorized DHCP server detection:
To do…
Use the command…
Remarks
Enter system view
system-view
—
Enable unauthorized DHCP server
detection
dhcp relay server-detect
Required
Disabled by default.
The device stores information about detected DHCP servers for the administrator to find unauthorized
DHCP servers. After the DHCP server information is cleared, the relay agent will re-record server
information.
Configuring the DHCP Relay Agent to Send a DHCP-Release Request
This task allows you to release a client’s IP address manually on the DHCP relay agent. After you
configure this task, the DHCP relay agent actively sends a DHCP-RELEASE request that contains the
client’s IP address to be released. Upon receiving the DHCP-RELEASE request, the DHCP server
then releases the IP address for the client; meanwhile, the client’s IP-to-MAC binding entry is removed
from the DHCP relay agent.
Follow these steps to configure the DHCP relay agent in system view to send a DHCP-RELEASE
request:
To do…
Use the command…
Remarks
Enter system view
system-view
—