Re: dhcp snooping

Abdullah Muslumanoglu <[email protected]>
Newsgroups gmane.comp.hardware.cisco.turkish
Message-ID <[email protected]>
DHCP server Core switch üzerinde ise kenar switch lerde yaptigin snooping çalışmayacaktır.
2 yol var;

1. DHCP server'ı kenar switchlerden birinin üzerine almak(bu durumda kenar switch'in down olması veya performansina bagli olarak ip alan client'ları riske atmis olursun)
2. DHCP Server core switch uzerinde ise core switch'te de snooping i enable etmek..

aklima simdilik bu geliyor.






________________________________
From: Cihan Akgün <[email protected]>
To: "[email protected]" <[email protected]>
Sent: Monday, 27 October, 2008 16:56:04
Subject: RE: [cisco-ttl] dhcp snooping


Abdullah Merhaba; 

Core switchler uzerinde dhcp snooping i enable etmek istemiyorum, zaten sadece kenar switchlerin portlarina disaridan erisim var.  Ben gonderidigim konfigurasyon da sadece kenar switchler uzerinde. Core da herhangi bir islem yapmadan bu isi gerceklestirebilir miyim? 

cakgun 

From: cisco-ttl@yahoogrou ps.com [mailto:cisco-ttl@yahoogrou ps.com] On Behalf Of Abdullah Muslumanoglu 
Sent: Monday, October 27, 2008 2:16 PM 
To: cisco-ttl@yahoogrou ps.com 
Subject: Re: [cisco-ttl] dhcp snooping 


Cihan, 

Eğer DHCP server'ın core switch'e bagli ise 3560 in portunda trust konfigurasyonu yaptığın gibi core switchlerde de yapman lazım, ayrıca core switchlerde hangi vlanlerin snooping islemine tabi tutulacagini da soylemelisin, dikkat etmen gereken nokta, core switcte snooping i aktif ettiğin anda tün trunk portlardan gelen client'lar bu trunk portları da trust etmeden ip alamayacaktır. tavsiyem 3560 a bir kenar switch takarak ufak bir lab olusturup önce test etmen..calistirirsa n haber ediver.. 

Core switch : 

(config)#ip dhcp snooping 

(config)#ip dhcp snooping vlan 20,30,40 

(config-if)# ip dhcp snooping trust (core sw de DHCP nin takılı olduğu port) 

(config-if)# ip dhcp snooping trust (core sw de kat sw imize giden trunk port) 

3560 switch : 

(config)#ip dhcp snooping 

(config)#ip dhcp snooping vlan 20,30,40 

(config-if)# ip dhcp snooping trust (core sw e giden trunk port) 

____________ _________ _________ __ 
From: Cihan Akgün <cihan.akgun@ zaman.com. tr<mailto:cihan. akgun%40zaman. com.tr>> 
To: "cisco-ttl@yahoogrou ps.com<mailto:cisco- ttl%40yahoogroup s.com>" <cisco-ttl@yahoogrou ps.com<mailto:cisco- ttl%40yahoogroup s.com>> 
Sent: Friday, 24 October, 2008 10:41:46 
Subject: [cisco-ttl] dhcp snooping 

Merhaba; 

Sirkette guvenlik acisindan icerideki kenar switchlerde dhcp snooping konfigurasyonunu enable etmek istiyorum. Bir takim test konfigurasyonlari yaptim fakat sonuc alamadim. Yapiyi aciklamam gerekirse hsrp ile redundant calisan 2 adet core switch uzerinde yaklasik 40 vlan in oldugu vlan interface leri var. DHCP server bu vlanlarlandan bir tanesinin icerisinde ve Core switchlerde vlan interface lerinin altinda ip helper address komutuyla dhcp server I tanimladim. Kenar switchlerdeki tum userlar hangi vlan da olurlarsa olsunlar ip alabiliyorlar. Daha sonra core switch e trunk linkler ile 3560g bir test switch I bagladim. Test switchin gi0/48 portunu trunk olarak tanimladim. Sonra asagidaki konfigurasyonu yaptim, fakat bu switchdeki userlar ip alamadilar. 

3560G konfigurasyonu 

ip dhcp snooping vlan 1-35 
ip dhcp snooping 
! 
! 
! 
errdisable recovery cause psecure-violation 
errdisable recovery interval 30 
! 
interface GigabitEthernet0/ 1 
description test-client 
switchport access vlan 14 
switchport mode access 
switchport port-security 
switchport port-security aging time 1 
switchport port-security violation restrict 
! 
interface GigabitEthernet0/ 48 
desc uplink 
switchport trunk encapsulation dot1q 
switchport mode trunk 
ip dhcp snooping trust 

yukaridaki configler haricinde herhangi bir ayar yapmadim. Yardimci olabilirseniz sevinirim. 

Simdiden tesekkurler 

Cihan Akgun 

[Non-text portions of this message have been removed] 

[Non-text portions of this message have been removed] 


[Non-text portions of this message have been removed]

    


      

[Non-text portions of this message have been removed]


------------------------------------

--
Cisco Teknik Tartisma Listesi (Cisco-ttl)

Bu listede onerilen degisikliklerin uygulanmasindaki tum sorumluluk 
kullaniciya aittir. Liste yoneticileri, oneride bulunan liste uyeleri ya da 
bu uyelerin calistigi kuruluslar herhangi bir sekilde sorumlu tutulamazlar.Yahoo! Groups Links

<*> To visit your group on the web, go to:
    http://groups.yahoo.com/group/cisco-ttl/

<*> Your email settings:
    Individual Email | Traditional

<*> To change settings online go to:
    http://groups.yahoo.com/group/cisco-ttl/join
    (Yahoo! ID required)

<*> To change settings via email:
    mailto:[email protected] 
    mailto:[email protected]

<*> To unsubscribe from this group, send an email to:
    [email protected]

<*> Your use of Yahoo! Groups is subject to:
    http://docs.yahoo.com/info/terms/
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.