Коммутатор DES-3200-28, ревизия C1, прошивка 4.36.B009
На коммутаторе на строен dhcp_relay, клиент получает адрес от dhcp сервера на основании option82, все работает.
Пробую настроить address_binding с dhcp_snoop чтобы клиент не мог менять свой ip. И тут проблема - при получении клиентом ip адреса в address_binding не вносятся данные о нем, т.е. вывод команд
show address_binding dhcp_snoop binding_entry
show address_binding blocked all
пустые. Соответственно клиент меняет себе адрес и у него продолжает все работать.
Пробовал включить debug address_binding all - ни в логах, ни в консоли никаких сообщений не было.
Конфиг:
Код:
Command: show config current_config include "dhcp"
config address_binding dhcp_snoop max_entry ports 1 limit 2
config address_binding dhcp_snoop max_entry ports 2 limit 2
config address_binding dhcp_snoop max_entry ports 3 limit 2
config address_binding dhcp_snoop max_entry ports 4 limit 2
config address_binding dhcp_snoop max_entry ports 5 limit 2
config address_binding dhcp_snoop max_entry ports 6 limit 2
config address_binding dhcp_snoop max_entry ports 7 limit 2
config address_binding dhcp_snoop max_entry ports 8 limit 2
config address_binding dhcp_snoop max_entry ports 9 limit 2
config address_binding dhcp_snoop max_entry ports 10 limit 2
config address_binding dhcp_snoop max_entry ports 11 limit 2
config address_binding dhcp_snoop max_entry ports 12 limit 2
config address_binding dhcp_snoop max_entry ports 13 limit 2
config address_binding dhcp_snoop max_entry ports 14 limit 2
config address_binding dhcp_snoop max_entry ports 15 limit 2
config address_binding dhcp_snoop max_entry ports 16 limit 2
config address_binding dhcp_snoop max_entry ports 17 limit 2
config address_binding dhcp_snoop max_entry ports 18 limit 2
config address_binding dhcp_snoop max_entry ports 19 limit 2
config address_binding dhcp_snoop max_entry ports 20 limit 2
config address_binding dhcp_snoop max_entry ports 21 limit 2
config address_binding dhcp_snoop max_entry ports 22 limit 2
config address_binding dhcp_snoop max_entry ports 23 limit no_limit
config address_binding dhcp_snoop max_entry ports 24 limit no_limit
config address_binding dhcp_snoop max_entry ports 25 limit no_limit
config address_binding dhcp_snoop max_entry ports 26 limit no_limit
config address_binding dhcp_snoop max_entry ports 27 limit no_limit
config address_binding dhcp_snoop max_entry ports 28 limit no_limit
enable address_binding dhcp_snoop
disable address_binding dhcp_snoop ipv6
config address_binding dhcp_snoop max_entry ports 1-28 limit no_limit ipv6
config filter dhcp_server ports all state disable
config filter dhcp_server illegal_server_log_suppress_duration 5min
config filter dhcp_server trap_log disable
config ipif System dhcp_option12 state disable
disable dhcp_local_relay
config dhcp_local_relay option_82 remote_id default
config dhcp_local_relay option_82 circuit_id default
config dhcp_local_relay option_82 ports 1-28 policy keep
enable dhcp_relay
config dhcp_relay hops 4 time 0
config dhcp_relay option_82 state enable
config dhcp_relay option_82 check enable
config dhcp_relay option_82 policy replace
config dhcp_relay option_82 remote_id default
config dhcp_relay option_82 circuit_id default
config dhcp_relay option_60 state disable
config dhcp_relay option_61 state disable
config dhcp_relay add ipif System 172.16.0.10
config dhcp_relay add ipif System 172.16.0.30
config dhcp_relay option_60 default mode drop
config dhcp_relay option_61 default drop
config dhcp_relay ports 1-22,25-28 state enable
config dhcp_relay ports 23-24 state disable
До 22 порта клиенты, 24 порт аплинк.
Куда смотреть?