Huawei Quidway S9300 Configuration Manual page 87

Terabit routing switch v100r001c03
Table of Contents

Advertisement

Quidway S9300 Terabit Routing Switch
Configuration Guide - Security
<Quidway> system-view
[Quidway] dhcp snooping enable
# Enable DHCP snooping on the interface. You can perform other DHCP snooping
configurations only after DHCP snooping is enabled on the interfaces at the DHCP server side
and user side.
[Quidway] interface gigabitethernet 1/0/0
[Quidway-GigabitEthernet1/0/0] dhcp snooping enable
[Quidway-GigabitEthernet1/0/0] quit
[Quidway] interface gigabitethernet 2/0/0
[Quidway-GigabitEthernet2/0/0] dhcp snooping enable
[Quidway-GigabitEthernet2/0/0] quit
Step 2 Configure the checking of packets.
# Configure the checking of DHCP Request messages on the user-side interface.
[Quidway] interface gigabitethernet 2/0/0
[Quidway-GigabitEthernet2/0/0] dhcp snooping check user-bind enable
[Quidway-GigabitEthernet2/0/0] quit
Step 3 Configure static binding entries.
# Configure static binding entries assigned to the user side.
[Quidway] user-bind static ip-address 10.1.1.3 mac-address 0000-005e-008a
interface gigabitethernet 2/0/0 vlan 3
Step 4 Configure the packet discarding alarm function.
# Enable the packet discarding alarm function.
[Quidway] interface gigabitethernet 2/0/0
[Quidway-GigabitEthernet2/0/0] dhcp snooping alarm user-bind enable
# Set the alarm threshold.
[Quidway-GigabitEthernet2/0/0] dhcp snooping alarm user-bind threshold 120
Step 5 Configure the Option 82 function.
# Configure the user-side interface to append the Option 82 field to DHCP messages.
[Quidway] interface gigabitethernet 2/0/0
[Quidway-GigabitEthernet2/0/0] dhcp option82 insert enable
[Quidway-GigabitEthernet2/0/0] quit
Step 6 Verify the configuration.
Run the display dhcp snooping command on the S9300, and you can view that DHCP snooping
is enabled globally and on the interface.
<Quidway> display dhcp snooping global
dhcp snooping enable
<Quidway> display dhcp snooping interface gigabitethernet 2/0/0
dhcp snooping enable
dhcp snooping check user-bind enable
dhcp snooping alarm user-bind enable
dhcp snooping alarm user-bind threshold 120
user-bind total
mac-address&src mac total
untrust-reply total
Run the display user-bind all command, and you can view all the binding entries of users.
<Quidway> display user-bind all
bind-table:
Issue 01 (2009-07-28)
45
0
0
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
2 DHCP Snooping Configuration
2-31

Advertisement

Table of Contents
loading

Table of Contents