Example For Enabling Dhcp Snooping On The Dhcp Relay Agent - Huawei Quidway S9300 Configuration Manual

Terabit routing switch
Table of Contents

Advertisement

3 DHCP Snooping Configuration
dhcp snooping check dhcp-rate alarm enable
dhcp snooping check dhcp-rate 90
dhcp snooping check dhcp-rate alarm threshold 80
#
user-bind static ip-address 10.1.1.1 mac-address 0001-0002-0003 interface
gigabitethernet 1/0/1 vlan 10
#
interface GigabitEthernet1/0/0
dhcp snooping enable
dhcp snooping alarm untrust-reply enable
dhcp snooping alarm untrust-reply threshold 120
dhcp snooping check mac-address enable
dhcp snooping alarm mac-address enable
dhcp snooping alarm mac-address threshold 120
dhcp snooping check user-bind enable
dhcp snooping alarm user-bind enable
dhcp snooping alarm user-bind threshold 120
dhcp option82 insert enable
#
interface GigabitEthernet1/0/1
dhcp snooping enable
dhcp snooping alarm untrust-reply enable
dhcp snooping alarm untrust-reply threshold 120
dhcp snooping check mac-address enable
dhcp snooping alarm mac-address enable
dhcp snooping alarm mac-address threshold 120
dhcp snooping check user-bind enable
dhcp snooping alarm user-bind enable
dhcp snooping alarm user-bind threshold 120
dhcp option82 insert enable
#
interface GigabitEthernet2/0/0
dhcp snooping trusted
#
return
3.10.6 Example for Enabling DHCP Snooping on the DHCP Relay
Agent
Networking Requirements
As shown in
DHCP relay function is enabled; DHCP client1 uses the dynamically allocated IP address and
DHCP client2 uses the statically configured IP address. It is required that DHCP snooping be
configured on the S9300 to prevent the following types of attacks:
l
l
l
l
When users log out abnormally after requesting for IP addresses, the system detects this failure
automatically, and then deletes the binding in the DHCP binding table, and notifies the DHCP
server to release IP addresses.
3-46
Figure
3-8, the S9300 is connected to the DHCP server and DHCP client; the
Bogus DHCP server attack
DoS attack by changing the value of the CHADDR field
Attack by sending bogus messages for extending IP address leases
Attack by sending a large number of DHCP Request messages
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
Quidway S9300 Terabit Routing Switch
Configuration Guide - Security
Issue 06 (2010–01–08)

Advertisement

Table of Contents
loading

Table of Contents