Huawei Quidway S9300 Configuration Manual page 154

Terabit routing switch
Table of Contents

Advertisement

3 DHCP Snooping Configuration
[Quidway] interface gigabitethernet 1/0/0
[Quidway-GigabitEthernet1/0/0] dhcp snooping check user-bind enable
[Quidway-GigabitEthernet1/0/0] quit
# Enable the checking of the CHADDR field on the interfaces at the DHCP client side to prevent
attackers from changing the CHADDR field in DHCP Request messages. The configuration of
GE 1/0/1 is the same as the configuration of GE 1/0/0, and is not mentioned here.
[Quidway] interface gigabitethernet 1/0/0
[Quidway-GigabitEthernet1/0/0] dhcp snooping check mac-address enable
[Quidway-GigabitEthernet1/0/0] quit
Step 4 Configure the DHCP snooping binding table.
# If you use the static IP address, configuring DHCP snooping static entries is required.
[Quidway] user-bind static ip-address 10.1.1.1 mac-address 0001-0002-0003
interface gigabitethernet 1/0/1 vlan 10
Step 5 Limit the rate of sending DHCP messages.
# Check the rate of sending DHCP messages to prevent attackers from sending DHCP Request
messages.
[Quidway] dhcp snooping check dhcp-rate enable
[Quidway] dhcp snooping check dhcp-rate 90
Step 6 Configure the Option 82 function.
# Configure the user-side interface to append the Option 82 field to DHCP messages. The
configuration of GE 1/0/1 is the same as the configuration of GE 1/0/0, and is not mentioned
here.
[Quidway] interface gigabitethernet 1/0/0
[Quidway-GigabitEthernet1/0/0] dhcp option82 insert enable
[Quidway-GigabitEthernet1/0/0] quit
Step 7 Configure the packet discarding alarm function.
# Enable the packet discarding alarm function, and set the alarm threshold of the number of
discarded packets. The configuration of GE 1/0/1 is the same as the configuration of GE 1/0/0,
and is not mentioned here.
[Quidway] interface gigabitethernet 1/0/0
[Quidway-GigabitEthernet1/0/0] dhcp snooping alarm mac-address enable
[Quidway-GigabitEthernet1/0/0] dhcp snooping alarm user-bind enable
[Quidway-GigabitEthernet1/0/0] dhcp snooping alarm untrust-reply enable
[Quidway-GigabitEthernet1/0/0] dhcp snooping alarm mac-address threshold 120
[Quidway-GigabitEthernet1/0/0] dhcp snooping alarm user-bind threshold 120
[Quidway-GigabitEthernet1/0/0] dhcp snooping alarm untrust-reply threshold 120
[Quidway-GigabitEthernet1/0/0] quit
# Enable the alarm function for checking the rate of sending packets, and set the alarm threshold
for checking the rate of sending packets.
[Quidway] dhcp snooping check dhcp-rate alarm enable
[Quidway] dhcp snooping check dhcp-rate alarm threshold 80
Step 8 Verify the configuration.
Run the display dhcp snooping global command on the S9300, and you can view that DHCP
snooping is enabled globally. You can also view the statistics on alarms.
[Quidway] display dhcp snooping global
dhcp snooping enable
dhcp snooping check dhcp-rate enable
dhcp snooping check dhcp-rate 90
3-44
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
Quidway S9300 Terabit Routing Switch
Configuration Guide - Security
Issue 06 (2010–01–08)

Advertisement

Table of Contents
loading

Table of Contents