Introduction To Ip Filtering - H3C S3100-52P Operation Manual

Hide thumbs Also See for S3100-52P:
Table of Contents

Advertisement

Operation Manual – DHCP
H3C S3100-52P Ethernet Switch
Table 2-2 Ways of handling a DHCP packet without Option 82
Sub-option configuration
Neither of the two sub-options
is configured.
Circuit ID sub-option is
configured.
Remote ID sub-option is
configured.
Note:
The circuit ID and remote ID sub-options in Option 82, which can be configured
simultaneously or separately, are independent of each other in terms of configuration
sequence.
When the DHCP snooping device receives a DHCP response packet from the DHCP
server, the DHCP snooping device will delete the Option 82 field, if contained, before
forwarding the packet, or will directly forward the packet if the packet does not contain
the Option 82 field.

2.1.3 Introduction to IP Filtering

A denial-of-service (DoS) attack means an attempt of an attacker sending a large
number of forged address requests with different source IP addresses to the server so
that the network cannot work normally. The specific effects are as follows:
The resources on the server are exhausted, so the server does not respond to
other requests.
After receiving such type of packets, a switch needs to send them to the CPU for
processing. Too many request packets cause high CPU usage rate. As a result,
the CPU cannot work normally.
The switch can filter invalid IP packets through the DHCP-snooping table and IP
static binding table.
I. DHCP-snooping table
After DHCP snooping is enabled on a switch, a DHCP-snooping table is generated. It is
used to record IP addresses obtained from the DHCP server, MAC addresses, the
number of the port through which a client is connected to the DHCP-snooping-enabled
Chapter 2 DHCP Snooping Configuration
The DHCP-Snooping device will ...
Forward the packet after adding Option 82 with the
default contents.
The format of Option 82 is the one specified with
the dhcp-snooping information format
command or the default HEX format if this
command is not executed.
Forward the packet after adding Option 82 with the
configured circuit ID sub-option in ASCII format.
Forward the packet after adding Option 82 with the
configured remote ID sub-option in ASCII format.
2-5

Advertisement

Table of Contents
loading

Table of Contents