Checking The Configuration; Limiting The Rate Of Sending Dhcp Messages; Establishing The Configuration Task - Huawei Quidway S3700 Series Configuration Manual

Hide thumbs Also See for Quidway S3700 Series:
Table of Contents

Advertisement

Quidway S3700 Series Ethernet Switches
Configuration Guide - Security
MAC addresses of static users in the static binding table cannot be converted to static MAC
addresses. You need to configure static MAC addresses for the static users to have the packets
forwarded normally.
Step 4 (Optional) Run:
undo mac-address snooping [ interface-type interface-number [ vlan vlan-id ] |
vlan vlan-id [interface-type interface-number ] ]
The static MAC entries converted from dynamic binding entries by the dhcp snooping sticky-
mac command are deleted.
----End

3.6.5 Checking the Configuration

This section describes how to check the configuration of the maximum number of DHCP
snooping users.
Prerequisite
The configurations of setting the maximum number of users are complete.
Procedure
l
l
l
----End

3.7 Limiting the Rate of Sending DHCP Messages

This section describes how to prevent attackers from sending a large number of DHCP Request
messages to attack the S3700.

3.7.1 Establishing the Configuration Task

Establishing the Configuration Task of Limiting the Rate of Sending DHCP Messages.
Applicable Environment
If an attacker sends DHCP messages continuously on a network, the DHCP protocol stack of
the S3700 is affected.
To prevent an attacker from sending a large number of DHCP messages, you can configure
DHCP snooping on the S3700 to check DHCP messages and limit the rate of sending DHCP
messages. Only a certain number of DHCP messages can be sent to the protocol stack during a
certain period. Excessive DHCP messages are discarded.
Issue 01 (2011-07-15)
Run the display dhcp snooping global command to check information about global DHCP
snooping.
Run the display dhcp snooping interface interface-type interface-number command to
check information about DHCP snooping on an interface.
Run the display mac-address snooping [ interface-type interface-number [ vlan vlan-
id ] | vlan vlan-id [interface-type interface-number ] ] [ verbose ] view static MAC address
entries converted from dynamic MAC address entries by the dhcp snooping sticky-mac
command.
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
3 DHCP Snooping Configuration
109

Advertisement

Table of Contents
loading

Table of Contents