防止局域网内私自IP地址(DHCP)

豆豆网   技术应用频道   2007年09月22日  【字号: 收藏本文

内容摘要:由于楼内经常存在私开的DHCP服务器,导致大量主机无法分配到合法IP地址;另外,由于有相当数量的主机指定IP地址,因此造成了与DHCP分配的IP地址冲突。以上两方面,均造成了该公寓楼大量主机无法正常访问网络。

  接下来配置Dynamic ARP Inspection

  1 show cdp neighbors 检查交换机之间的连接情况

  Capability Codes: R - Router, T - Trans Bridge, B - Source Route Bridge

  S - Switch, H - Host, I - IGMP, r - Repeater, P - Phone

  Device ID Local Intrfce Holdtme Capability Platform Port ID

  ap Gig 1/0/23 149 T AIR-AP1230Fas 0

  hall-3750 Gig 1/0/27 135 S I WS-C3750-2Gig 1/0/1

  1#west-3750 Gig 1/0/28 173 S I WS-C3750G-Gig 1/0/25

  2 configure terminal 进入全局配置模式

  3 ip arp inspection vlan 103 在VLAN 103上启用Dynamic ARP Inspection

  4 interface GigabitEthernet1/0/28 进入第28端口

  5 ip arp inspection trust 将端口设置为受信任端口

  The switch does not check ARP packets that it receives from the other switch on the trusted interface. It simply forwards the packets.

  6 end

  配置完成后可以用如下命令观察Dynamic ARP Inspection的运行情况

  show arp access-list [acl-name] Displays detailed information about ARP ACLs.

  show ip arp inspection interfaces [interface-id] Displays the trust state and the rate limit of ARP packets for the specified interface or all interfaces.

  Interface Trust State Rate (pps) Burst Interval

  --------------- ----------- ---------- --------------

  Gi1/0/21 Untrusted 15 1

  Gi1/0/22 Trusted None N/A

  Gi1/0/23 Untrusted 15 1

  Gi1/0/24 Trusted None N/A

  Gi1/0/25 Untrusted 15 1

责编:豆豆技术应用

正在加载评论...