华为交换机dhcp选用物理接口吗 (思科交换机dhcp分配ip地址冲突)

DHCP实验

DHCP报文介绍:

dhcp request:由用户向服务器的广播报文,目的是用来通知其他服务器是否使用服务器分配的IP地址,同时该报文还有续租的作用。Dhcp租期的目的是合理有效的使用IP地址,分配给客户端的IP地址都是有租期的,当达到租期一半的时候,客户端会自动触发续租消息(dhcp request)

思科交换机dhcp分配ip地址冲突,交换机固定ip后dhcp还会自动分配吗

DHCP实验拓扑

一、Dhcp全局配置步骤:

1、全局建立地址池

R2:

ip pool DHCP

gateway-list 192.168.1.1

network 192.168.1.0 mask 255.255.255.0

dns-list 8.8.8.8

interface Ethernet0/0/0

ip address 192.168.1.1 255.255.255.0

dhcp select global

2、修改租期:

ip pool DHCP

lease day 0 hour 23

3、绑定固定MAC配固定ip地址:

ip pool DHCP

static-bind ip-address 192.168.1.200 mac-address 5489-98B7-4274

4、排除地址段不自动分配:

ip pool DHCP

excluded-ip-address 192.168.1.250 192.168.1.254

5、调试命令:

dis ip pool interface vlanif100 used 显示dhcp哪些地址被使用

<>reset ip pool interface vlanif100 used 重置dhcp分配记录

二、基于接口的DHCP(配置简单)

R1:

dhcp enable

interface Ethernet0/0/0

ip address 192.168.1.1 255.255.255.0

dhcp select interface

dhcp server dns-list 8.8.8.8

三、dhcp relay (dhcp 中继)

思科交换机dhcp分配ip地址冲突,交换机固定ip后dhcp还会自动分配吗

DHCP实验(中继)

配置步骤:

R1:

dhcp enable

#

ip pool vlan10

gateway-list 192.168.10.1

network 192.168.10.0 mask 255.255.255.0

dns-list 8.8.8.8

#

ip pool vlan20

gateway-list 192.168.20.1

network 192.168.20.0 mask 255.255.255.0

dns-list 8.8.8.8

interface Ethernet0/0/0

ip address 192.168.100.2 255.255.255.0

dhcp select global

ip route-static 0.0.0.0 0.0.0.0 192.168.100.1

SW1:

vlan batch 10 20 100

dhcp enable

interface Vlanif10

ip address 192.168.10.1 255.255.255.0

dhcp select relay

dhcp relay server-ip 192.168.100.2

#

interface Vlanif20

ip address 192.168.20.1 255.255.255.0

dhcp select relay

dhcp relay server-ip 192.168.100.2

#

interface Vlanif100

ip address 192.168.100.1 255.255.255.0

interface GigabitEthernet0/0/1

port link-type access

port default vlan 100

#

interface GigabitEthernet0/0/2

port link-type trunk

port trunk allow-pass vlan 2 to 4094

#

interface GigabitEthernet0/0/3

port link-type trunk

port trunk allow-pass vlan 2 to 4094

SW2:

vlan 10

interface GigabitEthernet0/0/1

port link-type trunk

port trunk allow-pass vlan 10

#

interface GigabitEthernet0/0/2

port link-type access

port default vlan 10

Sw3:

vlan 20

interface GigabitEthernet0/0/1

port link-type trunk

port trunk allow-pass vlan 20

#

interface GigabitEthernet0/0/2

port link-type access

port default vlan 20

四、DHCP snooping 避免非法DHCP服务器接入网络,通常在接入交换机部署。

思科交换机dhcp分配ip地址冲突,交换机固定ip后dhcp还会自动分配吗

DHCP实验(DHCP snooping)

配置步骤:

R1:

dhcp enable

interface Ethernet0/0/0

ip address 192.168.1.1 255.255.255.0

dhcp select interface

dhcp server dns-list 9.9.9.9

R2:

dhcp enable

interface Ethernet0/0/0

ip address 192.168.31.1 255.255.255.0

dhcp select interface

dhcp server dns-list 8.8.8.8

SW1:

dhcp enable

dhcp snooping enable vlan 1 将vlan 1的所有接口设置snooping,都是非信任接口,非信任接口收到DHCP报文会直接丢弃。

interface GigabitEthernet0/0/1

dhcp snooping trusted 将上联接口设置为信任接口