Huawei Quidway S9300 Configuration Manual page 82

Terabit routing switch v100r001c03
Table of Contents

Advertisement

2 DHCP Snooping Configuration
Procedure
Step 1 Enable DHCP snooping.
# Enable DHCP snooping globally.
<Quidway> system-view
[Quidway] dhcp snooping enable
# Enable DHCP snooping on the interface. You can perform other DHCP snooping
configurations only after DHCP snooping is enabled on the interfaces at the DHCP server side
and user side.
[Quidway] interface gigabitethernet 1/0/0
[Quidway-GigabitEthernet1/0/0] dhcp snooping enable
[Quidway-GigabitEthernet1/0/0] quit
[Quidway] interface gigabitethernet 2/0/0
[Quidway-GigabitEthernet2/0/0] dhcp snooping enable
[Quidway-GigabitEthernet2/0/0] quit
[Quidway] interface gigabitethernet 2/0/0
[Quidway-GigabitEthernet2/0/0] dhcp snooping enable
[Quidway-GigabitEthernet2/0/0] quit
Step 2 Configure the interface as trusted or untrusted.
# Configure the interface at the DHCP server side as trusted.
[Quidway] interface gigabitethernet 1/0/0
[Quidway-GigabitEthernet1/0/0] dhcp snooping trusted
[Quidway-GigabitEthernet1/0/0] quit
# Configure the interface at the user side as untrusted.
After DHCP snooping is enabled on GE 2/0/0, the mode of GE 2/0/0 is untrusted by default.
Step 3 Configure the packet discarding alarm function.
# Configure the S9300 to discard the Reply messages received by the untrusted interfaces.
[Quidway] interface gigabitethernet 2/0/0
[Quidway-GigabitEthernet2/0/0] dhcp snooping alarm untrust-reply enable
# Set the alarm threshold.
[Quidway-GigabitEthernet2/0/0] dhcp snooping alarm untrust-reply threshold 120
[Quidway-GigabitEthernet2/0/0] quit
Step 4 Verify the configuration.
Run the display dhcp snooping command on the S9300, and you can view that DHCP snooping
is enabled globally and in the interface view.
<Quidway> display dhcp snooping global
dhcp snooping enable
<Quidway> display dhcp snooping interface gigabitethernet 1/0/0
dhcp snooping enable
dhcp snooping trusted
user-bind total
mac-address&src mac total
untrust-reply total
<Quidway> display dhcp snooping interface gigabitethernet 2/0/0
dhcp snooping enable
dhcp snooping alarm untrust-reply enable
dhcp snooping alarm untrust-reply threshold 120
user-bind total
2-26
0
0
0
0
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
Quidway S9300 Terabit Routing Switch
Configuration Guide - Security
Issue 01 (2009-07-28)

Advertisement

Table of Contents
loading

Table of Contents