Qtech QSW-3900-24-SFP-DC [160/245] Introduction dhcp snooping

Qtech QSW-3900-48-SFP-DC [160/245] Introduction dhcp snooping
QTECH Software Configuration Manual
11-159
QTECH(config)#no dhcp-relay
! Show DHCP relay status
QTECH(config)#show dhcp-relay
11.6.2 Configure vlan interface
Configure specified VLAN for relaying DHCP packets. It MUST be the same VLAN, like the PVID of
clients port.
Use for example this configuration for set the IP address of DHCP server and specify the interface VLAN
aliase :
QTECH(config)#vlan vlannumber
QTECH(config-if-vlan)#interface ipaddress mask gateway
QTECH(config-if-vlan)#dhcpserver ip ipadddress
11.6.3 Support relay option82
When relay devices receive the DHCP_DISCOVER and DHCP_REQUEST packet sent by client, add
option82 and send to server. After receiving the request packet of server, strip option82 before transmitting to client.
Enable option82 support
dhcp option82
Disable option82 support
no dhcp option82
Configure handling strategy of requiry packet contained option82
dhcp option82 strategy {drop|keep|replace}
Display configuration of option82
show dhcp option82
11.7 Introduction DHCP snooping
When DHCP servers are allocating IP addresses to the clients on the LAN, DHCP snooping can be
configured on LAN switches to harden the security on the LAN to only allow clients with specific IP/MAC addresses
to have access to the network.
DHCP snooping is a series of layer 2 techniques. It works with information from a DHCP server to :
· Track the physical location of hosts.
· Ensure that hosts only use the IP addresses assigned to them.
· Ensure that only authorized DHCP servers are accessible.
· In short, DHCP snooping ensures IP integrity on a Layer 2 switched domain.
With DHCP snooping, only a whitelist of IP addresses may access the network. The whitelist is configured at
the switch port level, and the DHCP server manages the access control. Only specific IP addresses with specific MAC
addresses on specific ports may access the IP network.
DHCP snooping also stops attackers from adding their own DHCP servers to the network. An
attacker-controlled DHCP server could wreak havoc in the network or even control it.
For the sake of security, the IP addresses used by online DHCP clients need to be tracked for the administrator
to verify the corresponding relationship between the IP addresses the DHCP clients obtained from DHCP servers and
the MAC addresses of the DHCP clients.
· Layer 3 switches can track DHCP client IP addresses through a DHCP relay agent.

Содержание

Скачать