Huawei Quidway S9300 Configuration Manual page 143

Terabit routing switch
Table of Contents

Advertisement

Quidway S9300 Terabit Routing Switch
Configuration Guide - Security
# Enable DHCP snooping on the user-side interface.
Step 2 Configure the interface as trusted or untrusted.
# Configure the interface at the DHCP server side as trusted.
[Quidway] interface gigabitethernet 1/0/0
[Quidway-GigabitEthernet1/0/0] dhcp snooping trusted
[Quidway-GigabitEthernet1/0/0] quit
# Configure the interface at the user side as untrusted.
After DHCP snooping is enabled on GE 2/0/0, the mode of GE 2/0/0 is untrusted by default.
Step 3 Configure the packet discarding alarm function.
# Configure the S9300 to discard the Reply messages received by the untrusted interfaces.
[Quidway] interface gigabitethernet 2/0/0
[Quidway-GigabitEthernet2/0/0] dhcp snooping alarm untrust-reply enable
# Set the alarm threshold.
[Quidway-GigabitEthernet2/0/0] dhcp snooping alarm untrust-reply threshold 120
[Quidway-GigabitEthernet2/0/0] quit
Step 4 Verify the configuration.
Run the display dhcp snooping command on the S9300, and you can view that DHCP snooping
is enabled globally and in the interface view.
<Quidway> display dhcp snooping global
dhcp snooping enable
Dhcp snooping enable is configured at these vlan :NULL
Dhcp snooping enable is configured at these interface :
GigabitEthernet2/0/0
Dhcp snooping trusted is configured at these interface :
GigabitEthernet1/0/0
Dhcp option82 insert is configured at these interface :NULL
Dhcp option82 rebuild is configured at these interface :NULL
dhcp packet drop count within alarm range : 0
dhcp packet drop count total : 60
<Quidway> display dhcp snooping interface gigabitethernet 1/0/0
dhcp snooping trusted
<Quidway> display dhcp snooping interface gigabitethernet 2/0/0
dhcp snooping enable
dhcp snooping alarm untrust-reply enable
dhcp snooping alarm untrust-reply threshold 120
dhcp packet dropped by untrust-reply checking = 60
----End
Configuration Files
#
sysname Quidway
#
dhcp enable
Issue 06 (2010–01–08)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
3 DHCP Snooping Configuration
3-33

Advertisement

Table of Contents
loading

Table of Contents