Huawei Quidway S9300 Configuration Manual page 92

Terabit routing switch v100r001c03
Table of Contents

Advertisement

2 DHCP Snooping Configuration
l
l
l
l
l
l
l
Procedure
Step 1 Enable DHCP snooping.
# Enable DHCP snooping globally.
<Quidway> system-view
[Quidway] dhcp snooping enable
# Enable DHCP snooping on the interface. You can perform other DHCP snooping
configurations only after DHCP snooping is enabled on user-side and network-side interfaces.
The configuration procedures of GE 1/0/1 and GE 2/0/0 are the same as the configuration
procedure of GE 1/0/0, and are not mentioned here.
[Quidway] interface gigabitethernet 1/0/0
[Quidway-GigabitEthernet1/0/0] dhcp snooping enable
[Quidway-GigabitEthernet1/0/0] quit
Step 2 Configure the interface as trusted.
# Configure the interface connecting to the DHCP server as trusted and enable DHCP snooping
on all the interfaces connecting to the DHCP client. If the interface on the client side is not
configured as trusted, the default mode of the interface is untrusted after DHCP snooping is
enabled on the interface. This prevents bogus DHCP server attacks.
[Quidway] interface gigabitethernet 2/0/0
[Quidway-GigabitEthernet2/0/0] dhcp snooping trusted
[Quidway-GigabitEthernet2/0/0] quit
Step 3 Configure the checking for certain types of packets.
# Enable the checking of DHCP Request messages on the interfaces at the DHCP client side to
prevent attackers from sending bogus DHCP messages for extending IP address leases. The
configuration of GE 1/0/1 is the same as the configuration of GE 1/0/0, and is not mentioned
here.
[Quidway] interface gigabitethernet 1/0/0
[Quidway-GigabitEthernet1/0/0] dhcp snooping check user-bind enable
[Quidway-GigabitEthernet1/0/0] quit
# Enable the checking of the CHADDR field on the interfaces at the DHCP client side to prevent
attackers from changing the CHADDR field in DHCP Request messages. The configuration of
GE 1/0/1 is the same as the configuration of GE 1/0/0, and is not mentioned here.
2-36
VLAN that the interface belongs to being 10
GE 1/0/0 and GE 1/0/1 configured as untrusted and GE 2/0/0 configured as trusted
Static IP address from which packets are forwarded being 10.1.1.1/24 and corresponding
MAC address being 0001-0002-0003
Rate of sending DHCP messages to the protocol stack being 90
Mode of the Option 82 function being insert
Alarm threshold of the number of discarded packets being 120
Alarm threshold for checking the rate of sending packets being 80
NOTE
This configuration example provides only the commands related to the DHCP snooping configuration.
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
Quidway S9300 Terabit Routing Switch
Configuration Guide - Security
Issue 01 (2009-07-28)

Advertisement

Table of Contents
loading

Table of Contents