Checking The Configuration - Huawei Quidway S9300 Configuration Manual

Terabit routing switch
Table of Contents

Advertisement

Quidway S9300 Terabit Routing Switch
Configuration Guide - Security
The Option 82 is appended to DHCP messages.
Or, run:
dhcp option82 rebuild enable
The Option 82 is forcibly appended to DHCP messages.
l
l
Step 4 Run:
quit
Return to the system view.
Step 5 (Optional) Run:
dhcp option82 [ circuit-id | remote-id ] format { default | common | extend | user-
defined text }
The format of the Option 82 field is set.
----End

3.5.5 Checking the Configuration

Prerequisite
The configurations of preventing the attacker from sending bogus DHCP messages for extending
IP address leases are complete.
Procedure
l
l
l
Issue 06 (2010–01–08)
After the dhcp option82 insert enable command is used, the Option 82 is appended to DHCP
messages if original DHCP messages do not carry the Option 82 field; If the DHCP message
contains an Option 82 field previously, the S9300 checks whether the Option 82 field contains
the Remote-id. If the Option 82 field contains the Remote-id, the S9300 retains the original
Option 82 field. If not, the S9300 inserts the Remote-id to the Option 82 field. By default,
the Remote-id is the MAC address of the S9300.
After the dhcp option82 rebuild enable command is used, the Option 82 field is appended
to DHCP messages if original DHCP messages do not carry the Option 82 field; the original
Option 82 field is removed and a new one is appended if the original DHCP messages carry
the Option 82 field.
NOTE
If the user-defined format of the Option 82 field is used, it is recommended that you specify the interface
type, interface number, and slot ID in text.
Run the display dhcp snooping global command to check information about global DHCP
snooping.
Run the display dhcp snooping interface interface-type interface-number command to
check information about DHCP snooping on the interface.
Run the display dhcp snooping user-bind{ all | ip-address ip-address | ipv6-address
ipv6-address | mac-address mac-address | interface interface-type interface-number |
vlan vlan-id [ interface interface-type interface-number ] } command to check the DHCP
snooping binding table.
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
3 DHCP Snooping Configuration
3-17

Advertisement

Table of Contents
loading

Table of Contents