Configuring An Interface As A Trusted Interface; Optional) Enabling Detection Of Bogus Dhcp Servers - Huawei Quidway S9300 Configuration Manual

Terabit routing switch
Table of Contents

Advertisement

3 DHCP Snooping Configuration

3.3.3 Configuring an Interface as a Trusted Interface

Context
Generally, the interface connected to the DHCP server is configured as trusted and other
interfaces are configured as untrusted.
After DHCP snooping is enabled on an interface, the interface is an untrusted interface by default.
Procedure
Step 1 Run:
system-view
The system view is displayed.
Step 2 Run:
interface interface-type interface-number
The interface view is displayed.
The interface is the network-side interface connected to the DHCP server.
Or, run:
vlan vlan-id
The VLAN view is displayed.
Step 3 In the interface viewRun:
dhcp snooping trusted [ no-user-binding ]
Or, in the VLAN view, run: dhcp snooping trusted interface interface-type interface-
number [ no-user-binding ]
The interface is configured as a trusted interface.
DHCP Reply messages sent from a trusted interface are forwarded and DHCP Request messages
sent from the trusted interface are discarded; DHCP Discover messages sent from an untrusted
interface are discarded.
If the no-user-binding keyword is not used in the command, a binding entry is created when
the interface receives a DHCP Ack message sent to a user who does not go online through the
local device. If this keyword is used in the command, no binding entry is created in this case.
When running the dhcp snooping trusted command in the VLAN view, the specified interface
must belong to the VLAN. Compared with the dhcp snooping trusted command run in the
interface view, the dhcp snooping trusted command run in the VLAN view is more accurate
because a specified interface in a specified VLAN can be configured as a trusted interface.
----End

3.3.4 (Optional) Enabling Detection of Bogus DHCP Servers

Context
After detection of bogus DHCP servers is enabled, the S9300 records IP addresses of the DHCP
servers contained in all DHCP Reply messages. If a DHCP Reply message is sent from an
3-8
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
Quidway S9300 Terabit Routing Switch
Configuration Guide - Security
Issue 06 (2010–01–08)

Advertisement

Table of Contents
loading

Table of Contents