Configuring Dhcp Server Security Functions; Prerequisites; Enabling Unauthorized Dhcp Server Detection - H3C S3100 Series Operation Manual

H3c s3100 series ethernet switches operation manual
Hide thumbs Also See for S3100 Series:
Table of Contents

Advertisement

Define new DHCP options. New configuration options will come out with DHCP development. To
support new options, you can add them into the attribute list of the DHCP server.
Extend existing DHCP options. When the current DHCP options cannot meet customers'
requirements (for example, you cannot use the dns-list command to configure more than eight
DNS server addresses), you can configure a self defined option for extension.
Follow these steps to customize the DHCP service:
To do...
Enter system view
Configure
customized
options
Be cautious when configuring self-defined DHCP options because such configuration may affect the
DHCP operation process.

Configuring DHCP Server Security Functions

DHCP security configuration is needed to ensure the security of DHCP service.

Prerequisites

Before configuring DHCP security, you should first complete the DHCP server configuration (either
global address pool-based or interface address pool-based DHCP server configuration).

Enabling Unauthorized DHCP Server Detection

If there is an unauthorized DHCP server in the network, when a client applies for an IP address, the
unauthorized DHCP server may assign an incorrect IP address to the client.
With this feature enabled, when receiving a DHCP message with the siaddr field not being 0 from a
client, the DHCP server will record the value of the siaddr field and the receiving interface. The
administrator can use such information to check out any DHCP unauthorized servers.
Follow these steps to enable unauthorized DHCP server detection:
Enter system view
system-view
interface interface-type interface-number
dhcp server option code { ascii
Configure the
ascii-string | hex hex-string&<1-10> |
current interface
ip-address ip-address&<1-8> }
quit
dhcp server option code { ascii
Configure
ascii-string | hex hex-string&<1-10> |
multiple
ip-address ip-address&<1-8> } { interface
interfaces in
interface-type interface-number [ to
system view
interface-type interface-number ] | all }
To do...
Use the command...
Use the command...
system-view
2-22
Remarks
Required
By default, no
customized
option is
configured.
Remarks

Advertisement

Chapters

Table of Contents
loading

Table of Contents