ZXR10 8900 Series User Manual (Basic Configuration Volume)
DHCP Snooping Preventing False
DHCP Server Configuration Example
DHCP server 1 connects with fei_1/1 of the switch. DHCP Server
1 is configured by administrator. DHCP server 2 connects with
fei_1/2 of switch, and it is a private and illegal server. Fei_1/1
and fei_1/2 belong to vlan100. Enable DHCP snooping function on
the switch to prevent setting false DHCP server in the network, as
shown in
Figure 21
.
At this time, it is required to enable DHCP snooping function in
vlan100 and set fei_1/1 as a trust port.
F
IGURE
21 DHCP S
NOOPING
P
REVENTING
F
ALSE
DHCP S
ERVER
Configuration on the switch:
ZXR10(config)#interface fei_1/1
ZXR10(config-if)#sw ac vlan 100
ZXR10(config)#interface fei_1/2
ZXR10(config-if)#sw ac vlan 100
ZXR10(config)#vlan 100
ZXR10(config-vlan)#ip dhcp snooping
ZXR10(config)#ip dhcp snooping enable
ZXR10(config)#ip dhcp snooping vlan 100
ZXR10(config)#ip dhcp snooping trust fei_1/1
DHCP Snooping Preventing Static IP
Configuration Example
DHCP server belongs to vlan100 and the PCs belong to vlan200.
The PC gets IP address through the server. At this time it is nec-
essary to forbid the PCs to set static IP address through DHCP
snooping and dynamic ARP inspection. This is shown in
Figure 22
.
70
Confidential and Proprietary Information of ZTE CORPORATION