Configuration Considerations; Configuration Procedures - H3C LS-5100-16P-SI-OVS-H3 Configuration

Low-end ethernet switches
Table of Contents

Advertisement

H3C Low-End Ethernet Switches Configuration Examples
ARP Attack Prevention
2.1.2 Network Diagram
VLAN10
Host area1
Eth1/0/4
TFTP server
IP:192.168.0.10/24
Figure 2-1 Network diagram for ARP attack prevention in DHCP snooping mode

2.1.3 Configuration Considerations

Enable DHCP snooping on Switch A and Switch B, and configure their ports
connected to the DHCP server as a DHCP snooping trusted port.
Configure an IP static binding entry for the TFTP server on Switch A.
Enable ARP attack detection on VLAN 10 of Switch A and VLAN 20 of Switch B
respectively, and configure their uplink ports as ARP trusted ports.
Configure ARP packet rate limit on the ports which directly connected to hosts of
Switch A and Switch B, and enable the port state auto-recovery function globally
on the two switches.

2.1.4 Configuration Procedures

I. Software version used
This example is configured and verified on S3100-EI series Ethernet switches
Release2104.
IP network
Vlan-int 10
192.168.0.1/24
Eth1/0/1
Gateway
Switch A
Eth1/0/1
Eth1/0/2
Eth1/0/3
Host A
Host B
2-2
Chapter 2 Configuration Examples
DHCP server
Eth1/0/3
Vlan-int 20
192.168.1.1/24
Eth1/0/2
Swtich B
Eth1/0/1
Eth1/0/4
Eth1/0/3
Host C
Host D
VLAN20
Host area2
Eth1/0/2
Host E

Advertisement

Table of Contents
loading

Table of Contents