Huawei Quidway S9300 Configuration Manual page 153

Terabit routing switch
Table of Contents

Advertisement

Quidway S9300 Terabit Routing Switch
Configuration Guide - Security
6.
7.
Data Preparation
To complete the configuration, you need the following data:
l
l
l
l
l
l
l
Procedure
Step 1 Enable DHCP snooping.
# Enable DHCP snooping globally.
<Quidway> system-view
[Quidway] dhcp enable
[Quidway] dhcp snooping enable
# Enable DHCP snooping on the interface at the user side. The configuration procedure of GE
1/0/1 is the same as the configuration procedure of GE 1/0/0, and is not mentioned here.
[Quidway] interface gigabitethernet 1/0/0
[Quidway-GigabitEthernet1/0/0] dhcp snooping enable
[Quidway-GigabitEthernet1/0/0] quit
Step 2 Configure the interface as trusted.
# Configure the interface connecting to the DHCP server as trusted and enable DHCP snooping
on all the interfaces connecting to the DHCP client. If the interface on the client side is not
configured as trusted, the default mode of the interface is untrusted after DHCP snooping is
enabled on the interface. This prevents bogus DHCP server attacks.
[Quidway] interface gigabitethernet 2/0/0
[Quidway-GigabitEthernet2/0/0] dhcp snooping trusted
[Quidway-GigabitEthernet2/0/0] quit
Step 3 Configure the checking for certain types of packets.
# Enable the checking of DHCP Request messages on the interfaces at the DHCP client side to
prevent attackers from sending bogus DHCP messages for extending IP address leases. The
configuration of GE 1/0/1 is the same as the configuration of GE 1/0/0, and is not mentioned
here.
Issue 06 (2010–01–08)
Configure the Option 82 function and create the binding table that contains information
about the interface.
Configure the packet discarding alarm function and the alarm function for checking the
rate of sending packets.
VLAN that the interface belongs to being 10
GE 1/0/0 and GE 1/0/1 configured as untrusted and GE 2/0/0 configured as trusted
Static IP address from which packets are forwarded being 10.1.1.1/24 and corresponding
MAC address being 0001-0002-0003
Rate of sending DHCP messages to the protocol stack being 90
Mode of the Option 82 function being insert
Alarm threshold of the number of discarded packets being 120
Alarm threshold for checking the rate of sending packets being 80
NOTE
This configuration example provides only the commands related to the DHCP snooping configuration.
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
3 DHCP Snooping Configuration
3-43

Advertisement

Table of Contents
loading

Table of Contents