3 DHCP Snooping Configuration
Figure 3-6 Networking diagram for limiting the rate for sending DHCP messages
DHCP client
Configuration Roadmap
The configuration roadmap is as follows:
1.
2.
3.
Data Preparation
To complete the configuration, you need the following data:
l
l
Procedure
Step 1 Enable DHCP snooping.
# Enable DHCP snooping globally.
<Quidway> system-view
[Quidway] dhcp enable
[Quidway] dhcp snooping enable
# Enable DHCP snooping on the user-side interface. The configuration procedure of GE 1/0/2
is the same as the configuration procedure of GE 1/0/1, and is not mentioned here.
[Quidway] interface gigabitethernet 1/0/1
[Quidway-GigabitEthernet1/0/1] dhcp snooping enable
[Quidway-GigabitEthernet1/0/1] quit
3-40
L2 network
GE1/0/2
Enable DHCP snooping globally and in the interface view.
Set the rate of sending DHCP Request messages to the protocol stack.
Configure the packet discarding alarm function.
Rate of sending DHCP Request messages
Alarm threshold
NOTE
This configuration example provides only the commands related to the DHCP snooping configuration.
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
Attacker
L2 network
GE1/0/1
GE2/0/1
DHCP relay
S9300
Quidway S9300 Terabit Routing Switch
Configuration Guide - Security
L3 network
DHCP server
Issue 06 (2010–01–08)