Huawei Quidway S9300 Configuration Manual page 93

Terabit routing switch v100r001c03
Table of Contents

Advertisement

Quidway S9300 Terabit Routing Switch
Configuration Guide - Security
[Quidway] interface gigabitethernet 1/0/0
[Quidway-GigabitEthernet1/0/0] dhcp snooping check mac-address enable
[Quidway-GigabitEthernet1/0/0] quit
Step 4 Configure the DHCP snooping binding table.
# If you use the static IP address, configuring DHCP snooping static entries is required.
[Quidway] user-bind static ip-address 10.1.1.1 mac-address 0001-0002-0003
interface gigabitethernet 1/0/1 vlan 10
Step 5 Limit the rate of sending DHCP messages.
# Check the rate of sending DHCP messages to prevent attackers from sending DHCP Request
messages.
[Quidway] dhcp snooping check dhcp-rate enable
[Quidway] dhcp snooping check dhcp-rate 90
Step 6 Configure the Option 82 function.
# Configure the user-side interface to append the Option 82 field to DHCP messages. The
configuration of GE 1/0/1 is the same as the configuration of GE 1/0/0, and is not mentioned
here.
[Quidway] interface gigabitethernet 1/0/0
[Quidway-GigabitEthernet1/0/0] dhcp option82 insert enable
[Quidway-GigabitEthernet1/0/0] quit
Step 7 Configure the packet discarding alarm function.
# Enable the packet discarding alarm function, and set the alarm threshold of the number of
discarded packets. The configuration of GE 1/0/1 is the same as the configuration of GE 1/0/0,
and is not mentioned here.
[Quidway] interface gigabitethernet 1/0/0
[Quidway-GigabitEthernet1/0/0] dhcp snooping alarm mac-address enable
[Quidway-GigabitEthernet1/0/0] dhcp snooping alarm user-bind enable
[Quidway-GigabitEthernet1/0/0] dhcp snooping alarm untrust-reply enable
[Quidway-GigabitEthernet1/0/0] dhcp snooping alarm mac-address threshold 120
[Quidway-GigabitEthernet1/0/0] dhcp snooping alarm user-bind threshold 120
[Quidway-GigabitEthernet1/0/0] dhcp snooping alarm untrust-reply threshold 120
[Quidway-GigabitEthernet1/0/0] quit
# Enable the alarm function for checking the rate of sending packets, and set the alarm threshold
for checking the rate of sending packets.
[Quidway] dhcp snooping check dhcp-rate alarm enable
[Quidway] dhcp snooping check dhcp-rate alarm threshold 80
Step 8 Verify the configuration.
Run the display dhcp snooping global command on the S9300, and you can view that DHCP
snooping is enabled globally. You can also view the statistics on alarms.
[Quidway] display dhcp snooping global
dhcp snooping enable
dhcp snooping check dhcp-rate enable
dhcp snooping check dhcp-rate alarm enable
dhcp snooping check dhcp-rate 90
dhcp snooping check dhcp-rate alarm threshold 80
Run the display dhcp snooping interface command, and you can view information about DHCP
snooping on the interface.
[Quidway] display dhcp snooping interface gigabitethernet 1/0/0
Issue 01 (2009-07-28)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
2 DHCP Snooping Configuration
2-37

Advertisement

Table of Contents
loading

Table of Contents