Chapter4ServiceConguration
zte(cfg)#setport49pvid10
zte(cfg)#configrouter
zte(cfg-router)#setipport0vlan10
zte(cfg-router)#setipport0ipaddressdhcp
zte(cfg-router)#setipport0enable
lCongurationVerication
zte(cfg-router)#showipport
IpPortStatusIpAddressMaskMacAddressVlanIdIpMode
---------------------------------------------------------------
0up100.1.1.5255.255.0.000.00.00.00.00.0210dhcp
4.26DHCPv6Conguration
DHCPv6Overview
DynamicHostCongurationProtocolofIPv6(DHCPv6)isusedbyanetworkhostto
dynamicallyapplyforhostcongurationfromaserver.
ZXR102900EseriessystemsupportsthefollowingDHCPv6functions:
1.DHCPv6snoopingfunction.DHCPv6serversandclientsdonotsupportauthentication
mechanism.DHCPv6serverscreatedillegallyandprivatelybringconfusiontoaddress
allocation,gatewayandDNSparametersofsomehosts.Asaresult,thesehosts
cannotconnecttoexternalnetworksproperly.Inaddition,thereareproblemssuch
asIPspoong,MACaddressspoonganduserIDspoongfromillegalclients,and
DHCPv6serveraddressexhaustion.OnthebasisofDHCPv6snooping,theOption82
technologycansolvethesesecurityproblemseffectively.
2.IPsourceguardfunction.BylisteningtotheDHCPv6interactionprocedurebetween
aclientandaserver,thesystemrecordstheIPaddressallocatedtotheclientbythe
server.ThesystemltersoutpacketswithothersourceIPaddressesonports,thus
preventingspoong.
ConguringDHCPv6
TheDHCPv6congurationincludesthefollowingcommands:
CommandFunction
zte(cfg)#setdhcpv6snooping{enable|disable}
EnablesordisablestheDHCPv6
snoopingfunctionglobally.
zte(cfg)#setdhcpv6snooping{add|delete}port<portlist>
EnablesordisablestheDHCPv6
snoopingfunctiononaport.
zte(cfg)#setdhcpv6port<1-28>{server|cascade|client}
Setstheattributeofaportinthe
DHCPv6snoopingfunction.
zte(cfg)#setdhcpv6ip-source-guard{add|delete}port<portlist>
Enablesordisablestheip-source-guard
functiononaport.
4-87
SJ-20120409144109-002|2012-07-02(R1.0)ZTEProprietaryandCondential