Huawei Quidway S3700 Series Configuration Manual page 138

Hide thumbs Also See for Quidway S3700 Series:
Table of Contents

Advertisement

Quidway S3700 Series Ethernet Switches
Configuration Guide - Security
<Quidway> system-view
[Quidway] dhcp enable
[Quidway] dhcp snooping enable
# Enable DHCP snooping on the user-side interface.
[Quidway] interface gigabitethernet 0/0/2
[Quidway-GigabitEthernet0/0/2] dhcp snooping enable
[Quidway-GigabitEthernet0/0/2] quit
Step 2 Configure the interface as the trusted interface or an untrusted interface.
# Configure the interface on the DHCP server side as the trusted interface.
[Quidway] interface gigabitethernet 0/0/1
[Quidway-GigabitEthernet0/0/1] dhcp snooping trusted
[Quidway-GigabitEthernet0/0/1] quit
# Configure the user-side interface as an untrusted interface.
After DHCP snooping is enabled on GE 0/0/2, GE 0/0/2 is an untrusted interface by default.
Step 3 Configure the function of checking DHCP Request messages and the alarm function for
discarded packets.
[Quidway] interface gigabitethernet 0/0/2
[Quidway-GigabitEthernet0/0/2] dhcp snooping check dhcp-request enable alarm dhcp-
request enable threshold 120
[Quidway-GigabitEthernet0/0/2] quit
Step 4 Check the DHCP snooping binding entries.
Run the display dhcp snooping user-bind all command, and you can view all the DHCP
snooping binding entries of users.
<Quidway> display dhcp snooping user-bind all
DHCP Dynamic Bind-table:
Flags:O - outer vlan ,I - inner vlan ,P - map vlan
IP Address
--------------------------------------------------------------------------------
10.1.1.3
2010.08.14-12:58
--------------------------------------------------------------------------------
print count:
Step 5 Verify the configuration.
Run the display dhcp snooping global command on the Switch, and you can view that DHCP
snooping is enabled globally and on the interface.
<Quidway> display dhcp snooping global
dhcp snooping enable
Dhcp snooping enable is configured at vlan :NULL
Dhcp snooping enable is configured at interface :
GigabitEthernet0/0/2
Dhcp snooping trusted is configured at interface :NULL
GigabitEthernet0/0/1
dhcp packet drop count within alarm range : 0
dhcp packet drop count total : 45
<Quidway> display dhcp snooping interface gigabitethernet 0/0/1
dhcp snooping trusted
dhcp packet dropped by untrust-reply checking = 0
<Quidway> display dhcp snooping interface gigabitethernet 0/0/2
dhcp snooping enable
dhcp snooping check dhcp-request enable alarm dhcp-request threshold 120
Issue 01 (2011-07-15)
MAC Address
VSI/VLAN(O/I/P) Interface
0000-005e-008a
3 /--
1
total count:
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
3 DHCP Snooping Configuration
/--
Ethernet0/0/2
1
Lease
125

Advertisement

Table of Contents
loading

Table of Contents