The dhcp option82-mismatch action offline command enables a device to log out an online user if the Option 82 information carried in the Discover packets, Request packets, or lease renewal packets of the user changes.
The undo dhcp option-mismatch action offline command restores the default configuration.
By default, a device does not log out an online user if the Option 82 information carried in the Discover packets, Request packets, or lease renewal packets of the user changes.
This command is supported only on the NetEngine 8000 F1A.
Usage Scenario
If the user information of an online IPv4 user is changed, the Option 82 information carried in a Discover packet, Request packet, or lease renewal packet sent by the new user will be different from that carried in such packets used for login of the old user. However, the new user is not logged out. To enable a device to log out a user and re-initiate a login authentication procedure in the preceding scenario, run the dhcp option82-mismatch action offline command. After the command is run, the device replies with a NAK message in response to such a Discover packet, Request packet, or lease renewal packet and starts the user logout process. The new user needs to be re-authenticated at a user login attempt. For dual-stack users in the preceding scenario, a device logs out a new dual-stack user only when the Option 82 information in a Discover packet, Request packet, or lease renewal packet of an IPv4 user is changed.
Prerequisites
Layer 2 user access has been configured using the access-type layer2-subscriber or access-type layer2-leased-line command in the BAS interface view.
The function to trust the access-line-id information has been enabled using the client-option82 command. Otherwise, the dhcp option82-mismatch action offline command configuration does not take effect.Precautions
In VS mode, this command is supported only by the admin VS.
The dhcp option82-mismatch action offline and access-line-id update online commands cannot be both run in the same bas interface view.<HUAWEI> system-view [~HUAWEI] interface GigabitEthernet0/1/17 [~HUAWEI-GigabitEthernet0/1/17] bas [~HUAWEI-GigabitEthernet0/1/17-bas] access-type layer2-subscriber default-domain authentication domain1 [*HUAWEI-GigabitEthernet0/1/17-bas] commit [~HUAWEI-GigabitEthernet0/1/17-bas] client-option82 [~HUAWEI-GigabitEthernet0/1/17-bas] dhcp option82-mismatch action offline