Huawei Quidway S9300 Configuration Manual page 96

Terabit routing switch v100r001c03
Table of Contents

Advertisement

2 DHCP Snooping Configuration
Configuration Roadmap
The configuration roadmap is as follows:
1.
2.
3.
4.
5.
6.
7.
Data Preparation
To complete the configuration, you need the following data:
l
l
l
l
l
l
l
Procedure
Step 1 Enable DHCP snooping.
# Enable DHCP snooping globally.
<Quidway> system-view
[Quidway] dhcp snooping enable
# Enable DHCP snooping on the interfaces.
[Quidway] interface gigabitethernet 1/0/0
[Quidway-GigabitEthernet1/0/0] dhcp snooping enable
[Quidway-GigabitEthernet1/0/0] quit
[Quidway] interface gigabitethernet 2/0/0
2-40
Enable DHCP snooping globally and in the interface view.
Configure interfaces to be trusted or untrusted to prevent bogus DHCP server attacks.
Configure the DHCP snooping binding table and check DHCP Request messages by
matching them with entries in the binding table to prevent attackers from sending bogus
DHCP messages for extending IP address leases.
Configure the checking of the CHADDR field in DHCP Request messages to prevent
attackers from changing the CHADDR field in DHCP Request messages.
Set the rate of sending DHCP Request messages to the protocol stack to prevent attackers
from sending a large number of DHCP Request messages.
Configure the Option 82 function and create the binding table that contains information
about the interface.
Configure the packet discarding alarm function and the alarm function for checking the
rate of sending packets.
GE 1/0/0 belonging to VLAN 10 and GE 2/0/0 belonging to VLAN 20
Static IP address from which packets are forwarded being 10.1.1.1/24 and corresponding
MAC address being 0001-0002-0003
GE 1/0/0 configured as untrusted and GE 2/0/0 configured as trusted
Rate of sending DHCP messages to the CPU being 90
Mode of the Option 82 function being insert
Alarm threshold of the number of discarded packets being 120
Alarm threshold for checking the rate of sending packets being 80
NOTE
This configuration example provides only the commands related to the DHCP snooping configuration.
For the configuration of DHCP Relay, see
Routing Switch Configuration Guide - IP Service.
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
Quidway S9300 Terabit Routing Switch
Configuring the DHCP Relay Agent
Configuration Guide - Security
in Quidway S9300 Terabit
Issue 01 (2009-07-28)

Advertisement

Table of Contents
loading

Table of Contents