Limiting The Rate Of Sending Dhcp Messages; Establishing The Configuration Task - Huawei Quidway S9300 Configuration Manual

Terabit routing switch
Table of Contents

Advertisement

3 DHCP Snooping Configuration
Prerequisite
The configurations of setting the maximum number of users are complete.
Procedure
l
l
----End

3.7 Limiting the Rate of Sending DHCP Messages

This section describes how to prevent attackers from sending a large number of DHCP Request
messages to attack the S9300.

3.7.1 Establishing the Configuration Task

3.7.2 Enabling DHCP Snooping
3.7.3 Limiting the Rate of Sending DHCP Messages
3.7.4 Checking the Configuration
3.7.1 Establishing the Configuration Task
Applicable Environment
If an attacker sends DHCP Request messages continuously on a network, the DHCP protocol
stack of the S9300 is affected.
To prevent an attacker from sending a large number of DHCP Request messages, you can
configure DHCP snooping on the S9300 to check DHCP Request messages and limit the rate
of sending DHCP Request messages. Only a certain number of DHCP Request messages can
be sent to the protocol stack during a certain period. Excessive DHCP Request messages are
discarded.
Pre-configuration Tasks
Before limiting the rate of sending packets, complete the following tasks:
l
l
Data Preparation
To limit the rate of sending packets, you need the following data.
3-22
Run the display dhcp snooping global command to check information about global DHCP
snooping.
Run the display dhcp snooping interface interface-type interface-number command to
check information about DHCP snooping on an interface.
Configuring the DHCP server
Configuring the DHCP relay agent
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
Quidway S9300 Terabit Routing Switch
Configuration Guide - Security
Issue 06 (2010–01–08)

Advertisement

Table of Contents
loading

Table of Contents