Huawei Quidway S9300 Configuration Manual page 162

Terabit routing switch
Table of Contents

Advertisement

3 DHCP Snooping Configuration
Configuration Roadmap
The configuration roadmap is as follows:
1.
2.
Data Preparation
To complete the configuration, you need the following data:
l
l
l
l
l
l
Procedure
Step 1 Configure the VPLS.
1.
3-52
Configure the VPLS, which involves the following:
Configure the routing protocol on the backbone network to ensure the connectivity of
l
routers.
Configure basic MPLS functions and establish an LSP between PEs.
l
Enable MPLS L2VPN on PEs.
l
Create a VSI on the PEs and specify LDP as the signaling protocol, and then bind the
l
VSI to the AC interfaces.
Configure DHCP snooping, which involves the following:
Enable DHCP snooping in the system view and in the interface view, and enable DHCP
l
snooping over VPLS.
Configure interfaces as trusted or untrusted to prevent bogus DHCP server attacks.
l
Set the maximum number of DHCP snooping users to prevent malicious IP address
l
application. Malicious IP address application prevents authorized users applying for IP
addresses.
Configure the checking of the CHADDR value to prevent DoS attacks by changing the
l
value of the CHADDR field.
Configure the checking of DHCP Request messages against the DHCP snooping
l
binding table to prevent attacks by sending bogus messages for extending IP address
leases.
Configure Option 82 and create a binding table covering accurate interface information.
l
Configure the alarm function.
l
Static IP address from which packets are forwarded
Maximum number of users
Alarm threshold
VSI name and VSI ID
IP address of the peer and tunnel policy used for setting up the peer relation
Interface bound to a VSI
NOTE
The following example only provides the configuration procedure of the S9300. For details on the
configuration of other devices, see the related operation guides.
Configure an IGP on the MPLS backbone network. In this example, OSPF is adopted to
advertise routes.
Assign an IP address to each interface on PEs as shown in
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
Quidway S9300 Terabit Routing Switch
Configuration Guide - Security
Figure
3-9.
Issue 06 (2010–01–08)

Advertisement

Table of Contents
loading

Table of Contents