User's Manual Part 2
36JadeOSUserManual
00:50:ba:50:76:D8 13.0.6.237 300 D Gi 6/10
00:50:ba:50:76:D4 13.0.6.227 300 D Gi 6/10
SecurityCheck
Through binding table, DHCP snooping module determine whether the DHCP mes‐
sagesentbyuserislegalornot,andthenrejectillegalDHCPrequestifillegal.
Enabling MAC address detection, DHCP snooping can avoid attack by checking
whethertheMACaddress ofDHCPprotocolmatchwiththesourceMAC addressof
Ethernet.
To enable MACaddressdetectionofDHCPsnooping, usethefollowingcommandin
configmode:
ip dhcp snooping verify mac-address enable
BroadcastSuppression
JadeOScanautomaticallyrecordDHCPrequestinformationintoDHCPsnoopingses‐
siontablebyenablingDHCPsnooping.WhenreceivedbroadcastmessagefromDHCP
server,JadeOScanlookupthecorrespondinghostandexitportintheDHCPsnoop‐
ingtable,thenchangethebroadcastintounicast.Therefore,JadeOSachievesbroad‐
castsuppression.
To configur e the broadcast suppression in QinQ interface, use the following com‐
mand:
ip dhcp snooping enable
TodisplaytheDHCPsnoopingsessiontable,usethefollowingcommand:
show ip dhcp snooping session
6.6.5ARPWithDHCP
EnablingARPwithDHCP,DHCPwillissueARPtablethatcombineddistributedIPad‐
dressandMACaddressinclienttothesystem,atthesametime,disablethefunction
ofARPlearninginthespecifiedinterface.Therefore,ARPtableisstrictlycheckedby
DHCPsnooping,whichensuresthelegalityand
avoidtheARPcheatandinterfereto
theuseronlineandcommunication.
Forexample:
¾ EnableARPwithDHCPfunction:
Step1Configureupdatearpinaddresspool
(JadeOS) (config)#ip dhcp pool ABC
(JadeOS) (config-dhcp)#update arp
Step 2Configure ARP authorized in the interface of distributed IP, disable ARP
learningfunction:
(JadeOS) (config)#interface vlan 6