Allied Telesis AT-8700XL Series Configuration examples, X Configure a private VLAN for customers

Models: AT-8700XL Series AT-8600 Series Rapier i Series

1 26
Download 26 pages 29.76 Kb
Page 14
Image 14
Configuration examples

Configuration examples

Configuration examples

This section contains the following examples:

z"Configuring the switch for DHCP snooping, filtering and Option 82, when it is acting as a layer 2 switch" on page 14

z"Configuring the switch for DHCP snooping, filtering, and Option 82, when it is acting as a layer 3 BOOTP Relay Agent" on page 17

Configuring the switch for DHCP snooping, filtering and Option 82, when it is acting as a layer 2 switch

In a layer 2 switching environment, a switch configured with Option 82 snooping will snoop any client-originated DHCP packets and insert Option 82 information into it before forwarding the packet(s) to the DHCP server. In this sense it is a layer 2 relay agent; the packet source and destination addresses are not altered.

DHCP servers that are configured to recognise the relay agent information option (Option

82)may use the information to keep a log of switches and port numbers that IP addresses have been allocated to, and may also use the information for various address assignment policies.

The DHCP server echoes the option back verbatim to the relay agent in server-to-client replies, and the relay agent strips the option before forwarding the reply to the client. This process is shown in the following figure.

(1). DHCP Client sends request

 

 

(2). Layer 2 Relay Agent appends

 

(3). Option 82 enabled DHCP

 

 

 

 

 

 

 

 

Option 82 to client sourced

 

server allocates address

 

 

 

 

 

 

packets

 

and stores the

 

 

 

 

 

 

 

 

 

 

 

 

Option 82 information

 

 

 

 

 

 

(4). Layer 2 Relay Agent strips

 

 

Server sends offer, with

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Option 82 from the offer packet

 

Option 82 echoed

 

 

 

 

 

 

and forwards to client

 

to the layer 2 relay agent

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

XConfigure a private VLAN for customers:

create vlan="Customers" vid=48 private

A private VLAN provides security so customers will not be able to directly connect to or detect each other.

Page 14 AlliedWare™ OS How To Note: DHCP Snooping on Rapier-style switches

Page 14
Image 14
Allied Telesis AT-8700XL Series, Rapier i Series manual Configuration examples, X Configure a private VLAN for customers