382 
Figure 120 Network diagram 
 
 
Configuration procedure 
1.  Add all ports on Switch B to VLAN 10, and configure the IP address of VLAN-interface 10 on 
Switch A. (Details not shown.) 
2.  Configure DHCP address pool 0 on Switch A as a DHCP server. 
<SwitchA> system-view 
[SwitchA] dhcp enable 
[SwitchA] dhcp server ip-pool 0 
[SwitchA-dhcp-pool-0] network 10.1.1.0 mask 255.255.255.0 
3.  Configure Host A as DHCP client, and Host B as user. (Details not shown.) 
4.  Configure Switch B: 
# Enable DHCP snooping. 
<SwitchB> system-view 
[SwitchB] dhcp-snooping 
[SwitchB] interface gigabitethernet 1/0/3 
[SwitchB-GigabitEthernet1/0/3] dhcp-snooping trust 
[SwitchB-GigabitEthernet1/0/3] quit 
# Enable ARP detection for VLAN 10. 
[SwitchB] vlan 10 
[SwitchB-vlan10] arp detection enable 
# Configure the upstream port as a trusted port (a port is an untrusted port by default). 
[SwitchB-vlan10] interface gigabitethernet 1/0/3 
[SwitchB-GigabitEthernet1/0/3] arp detection trust 
[SwitchB-GigabitEthernet1/0/3] quit 
# Configure a static IP source guard binding entry on interface GigabitEthernet 1/0/2. 
[SwitchB] interface gigabitethernet 1/0/2 
[SwitchB-GigabitEthernet1/0/2] ip source binding ip-address 10.1.1.6 mac-address 
0001-0203-0607 vlan 10 
[SwitchB-GigabitEthernet1/0/2] quit