Allied Telesis AT-8700XL Series Configuration examples, Configure a private Vlan for customers

Page 14

Configuration examples

Configuration examples

This section contains the following examples:

z"Configuring the switch for DHCP snooping, filtering and Option 82, when it is acting as a layer 2 switch" on page 14

z"Configuring the switch for DHCP snooping, filtering, and Option 82, when it is acting as a layer 3 BOOTP Relay Agent" on page 17

Configuring the switch for DHCP snooping, filtering and Option 82, when it is acting as a layer 2 switch

In a layer 2 switching environment, a switch configured with Option 82 snooping will snoop any client-originated DHCP packets and insert Option 82 information into it before forwarding the packet(s) to the DHCP server. In this sense it is a layer 2 relay agent; the packet source and destination addresses are not altered.

DHCP servers that are configured to recognise the relay agent information option (Option

82)may use the information to keep a log of switches and port numbers that IP addresses have been allocated to, and may also use the information for various address assignment policies.

The DHCP server echoes the option back verbatim to the relay agent in server-to-client replies, and the relay agent strips the option before forwarding the reply to the client. This process is shown in the following figure.

(1). DHCP Client sends request

 

 

(2). Layer 2 Relay Agent appends

 

(3). Option 82 enabled DHCP

 

 

 

 

 

 

 

 

Option 82 to client sourced

 

server allocates address

 

 

 

 

 

 

packets

 

and stores the

 

 

 

 

 

 

 

 

 

 

 

 

Option 82 information

 

 

 

 

 

 

(4). Layer 2 Relay Agent strips

 

 

Server sends offer, with

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Option 82 from the offer packet

 

Option 82 echoed

 

 

 

 

 

 

and forwards to client

 

to the layer 2 relay agent

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

XConfigure a private VLAN for customers:

create vlan="Customers" vid=48 private

A private VLAN provides security so customers will not be able to directly connect to or detect each other.

Page 14 AlliedWare™ OS How To Note: DHCP Snooping on Rapier-style switches

Image 14
Contents AlliedWareTM OS IntroductionThis document contains the following contents Dhcp snooping Related How To NotesMinimum configuration Dhcp snooping database time-out Database survival across rebootsDatabase Verifying the status of snooped usersList of terms ARP SecurityStatic binding Trusted and non-trusted portsEnabling Dhcp snooping Completely removing the Dhcp snooping database So the database is emptyDhcp Option Dhcp Message Type = Dhcp Request Protocol detailsExample Packet Configuring Option Analysis Configuring filtering Dhcp filteringARP security To enable Dhcp snooping ARP securityDhcp snooping filter show command Resource considerationsExample on a Rapier If ARP security is enabled, addOr if ARP security is enabled, is Configuration examples Configure a private Vlan for customersAdd the untagged ports for the customers Enable Dhcp snooping and Option 82 supportAdd the tagged uplink ports to the Vlan Define the Dhcp snooping trusted portsCreate a traffic class for all upstream flow groups Create a set of QoS classifiersDefine the upstream QoS flow groups Configure two VLANs for layer 3 access to the Dhcp server Add ports to the VLANsFor layer 3 support, enable the Bootp Relay Define the Dhcp snooping trusted portCreate a set of QoS classifiers DHCPSNProcess 0b4333cc Dhcp Snooping pkt for Vlan From port TroubleshootingNo trusted ports configured DHCPSNProcess 0b4333cc TaggedNone UntaggedNoneDhcp client continually sends requests instead of a discover Maximum number of leases is exceededDhcpsnarp 01a6f5ec ARP to be forwarded, sender validated Switch is dropping ARPsManager set dhcpsnooping port=3 maxleases=2 Dhcpsnarp 02680e6c ARP to be forwarded, sender validated Trusted portsShow log command is also very useful Displaying log entriesAppendix 1 ISC Dhcp server C613-16086-00 REV B