Qtech QSW-3200-28FC [55/136] Dhcp snooping

Qtech QSW-3200-28T [55/136] Dhcp snooping
+7(495) 797-3311www.qtech.ru
Москва, Новозаводская ул., 18, стр. 1
44
Configure the first DHCP server for a VLAN
dhcpsever ip ip-address
Delete the first DHCP server for the current VLAN
no dhcpserver ip
Configure the second DHCP server for a VLAN
dhcpsever backupip ip-address
Delete the second DHCP server for the current VLAN
no dhcpserver backupip
Example:
! Configure the first DHCP server for VLAN 1
QTECH(config-if-vlan)#dhcp-server ip 192.168.1.1
! Delete the first DHCP server for VLAN 1
QTECH(config-if-vlan)#no dhcp-server ip
6.3 DHCP Snooping
It belongs to layer 2 function which allows switch to detect DHCP packet and record user’s IP
address information. This function cannot be enabled at the same with DHCP relay. When
enabling it, switch will filtrate all DHCP packet to CPU and transmit by layer 2 CPU.
To permit using valid DHCP server to distribute IP address, DHCP SNOOPING will divide
interfaces to be trust one and non-trust one. Only trust interface can receive and send DHCP
packet transmitted by DHCP server to prevent interference of invalid DHCP server.
In security, DHCP SNOOPING permits configuring the max DHCP client number of some
interface or VLAN too prevent malicious requiry attack.
6.3.1 Enable the function
Enable DHCP SNOOPING, which cannot be enabled at the same time with DHCP RELAY.
Enable DHCP SNOOPING
dhcp-snooping
6.3.2 Configure trust interface
Specify some interface to be the trust one. Generally, valid DHCP server connects to trust
interface.
Specify interface to be the trusy one
dhcp-snooping trust
6.3.3 Configure Max client number
Configure max client number of interface or VLAN to prevent malicious user’s IP require DOS
attack to protect DHCP server.
Configure max client number of interface/VLAN
dhcp-snooping max-clients num
6.3.4 Configure IP source guard
Prevent IP address stolen through IP source guard.
Configure interface IP source guard
ip-source-guard

Содержание

Похожие устройства

Скачать