No relevant resource is found in the selected language.

This site uses cookies. By continuing to browse the site you are agreeing to our use of cookies. Read our privacy policy>Search

Reminder

To have a better experience, please upgrade your IE browser.

upgrade

Fat AP and Cloud AP V200R008C00 CLI-based Configuration Guide

Rate and give feedback :
Huawei uses machine translation combined with human proofreading to translate this document to different languages in order to help you better understand the content of this document. Note: Even the most advanced machine translation cannot match the quality of professional translators. Huawei shall not bear any responsibility for translation accuracy and it is recommended that you refer to the English document (a link for which has been provided).
Configuring Strict STA IP Address Learning Through DHCP

Configuring Strict STA IP Address Learning Through DHCP

Context

When a STA associates with an RU, the following situation occurs after strict STA IP address learning through DHCP is enabled:
  • If the STA obtains an IP address through DHCP, the RU will automatically report the IP address to the central AP. The STA IP address can be used to maintain the mapping entries between STA IP addresses and MAC addresses.
  • If the STA uses a static IP address, configure related parameters to control the association of the STA with the RU.

Procedure

  1. Run:

    system-view

    The system view is displayed.

  2. Run:

    wlan

    The WLAN view is displayed.

  3. Run:

    vap-profile name profile-name

    The VAP profile view is displayed.

  4. Run:

    undo learn-client-address { ipv4 | ipv6 } disable

    STA address learning is enabled.

    By default, STA address learning is enabled.

  5. Strict STA IP address learning through DHCP is enabled.

    Run the learn-client-address dhcp-strict [ blacklist enable ] command to enable strict STA IP address learning through DHCP.

    If the STA uses a static IP address:
    • If blacklist enable is specified, the STA will be added to the dynamic blacklist of the RU and cannot associate with the RU before the blacklist entry ages.
    • If blacklist enable is not specified, the STA can associate with the RU and the RU does not learn the STA IP address. In this case, enable IPSG to prevent communication through bogus IP addresses.

    NOTE:
    • After strict STA IP address learning through DHCP is enabled, if the central AP has learned the STA IP address through DHCP or statically, the STA using a bogus IP address will not be added to the blacklist. In this case, enable IPSG to prevent services from the bogus IP address from running.
    • After strict STA IP address learning is enabled, it is recommended that you run the ip source check user-bind enable and arp anti-attack check user-bind enable commands to enable IP source guard and dynamic ARP inspection so that STAs cannot communicate with the network before obtaining an IP address through DHCP.

Translation
Download
Updated: 2019-01-11

Document ID: EDOC1000176006

Views: 116241

Downloads: 309

Average rating:
This Document Applies to these Products
Related Documents
Related Version
Share
Previous Next