User's Manual Part 2

36JadeOSUserManual
00:50:ba:50:76:D8 13.0.6.237 300 D Gi 6/10
00:50:ba:50:76:D4 13.0.6.227 300 D Gi 6/10
SecurityCheck
Through binding table, DHCP snooping module determine whether the DHCP mes
sagesentbyuserislegalornot,andthenrejectillegalDHCPrequestifillegal.
Enabling MAC address detection, DHCP snooping can avoid attack by checking
whethertheMACaddress ofDHCPprotocolmatchwiththesourceMAC addressof
Ethernet.
To enable MACaddressdetectionofDHCPsnooping, usethefollowingcommandin
configmode:
ip dhcp snooping verify mac-address enable
BroadcastSuppression
JadeOScanautomaticallyrecordDHCPrequestinformationintoDHCPsnoopingses
siontablebyenablingDHCPsnooping.WhenreceivedbroadcastmessagefromDHCP
server,JadeOScanlookupthecorrespondinghostandexitportintheDHCPsnoop
ingtable,thenchangethebroadcastintounicast.Therefore,JadeOSachievesbroad
castsuppression.
To configur e the broadcast suppression in QinQ interface, use the following com
mand:
ip dhcp snooping enable
TodisplaytheDHCPsnoopingsessiontable,usethefollowingcommand:
show ip dhcp snooping session
6.6.5ARPWithDHCP
EnablingARPwithDHCP,DHCPwillissueARPtablethatcombineddistributedIPad
dressandMACaddressinclienttothesystem,atthesametime,disablethefunction
ofARPlearninginthespecifiedinterface.Therefore,ARPtableisstrictlycheckedby
DHCPsnooping,whichensuresthelegalityand
avoidtheARPcheatandinterfereto
theuseronlineandcommunication.
Forexample:
¾ EnableARPwithDHCPfunction
Step1Configureupdatearpinaddresspool
(JadeOS) (config)#ip dhcp pool ABC
(JadeOS) (config-dhcp)#update arp
Step 2Configure ARP authorized in the interface of distributed IP, disable ARP
learningfunction:
(JadeOS) (config)#interface vlan 6