在核心交換機上配置DHCP做靜態繫結嚴格限制地址分配
拓撲圖
S5700作為核心裝置,配置DHCP,為辦公網路分配IP地址
S2700作為接入裝置
S5700配置
vlan 100
description bangong
interface GigabitEthernet0/0/1
port link-type trunk
port trunk allow-pass vlan 100
interface Vlanif100
ip address 192.168.10.254 255.255.255.0
S2700配置
vlan 100
description bangong
interface Ethernet0/0/1
port link-type trunk
port trunk allow-pass vlan 100
interface Ethernet0/0/2
port link-type access
port default vlan 100
interface Ethernet0/0/3
port link-type access
port default vlan 100
interface Ethernet0/0/4
port link-type access
port default vlan 100
開啟DHCP
dhcp enable
配置地址池,並做靜態繫結,PC1只能獲取到192.168.10.1 PC2只能獲取到192.168.10.2 剩餘地址保留,不做分配,防止外部人員接入。
ip pool bangong
gateway-list 192.168.10.254
network 192.168.10.0 mask 255.255.255.0
static-bind ip-address 192.168.10.1 mac-address 5489-98e7-7f28
static-bind ip-address 192.168.10.2 mac-address 5489-98d8-4d8c
excluded-ip-address 192.168.10.3 192.168.10.253
dns-list 8.8.8.8
在虛介面下啟用全域性dhcp
interface Vlanif100
ip address 192.168.10.254 255.255.255.0
dhcp select global
在PC上驗證分配的地址
PC1
PC2
我們斷開PC2網線,假設PC2沒有接入,驗證PC3是否能獲取DHCP分配給PC2的地址