Qtech QSW-8200-52T-AC — dHCP Snooping Commands User Manual for Network Security [62/79]

Превью страниц Страница 62 / 79
Qtech QSW-8200-28T-AC [62/79] Ip dhcp snooping binding arp
User Manual
Chapter 5. Commands for DHCP Snooping 62
www.qtech.ru
Usage Guide: Set the max number of defense actions to avoid the resource exhaustion
of the switch caused by attacks. If the number of alarm information is larger than the
set value, then the earliest defense action will be recovered forcibly in order to send
new defense actions.
Example: Set the number of port defense actions as 100.
switch(config)#ip dhcp snooping action 100
5.10 ip dhcp snooping binding
Command: ip dhcp snooping binding enable
no ip dhcp snooping binding enable
Function: Enable the DHCP Snooping binding funciton
Parameters: None.
Command Mode: Globe mode
Default Settings: DHCP Snooping binding is disabled by default.
Usage Guide: When the function is enabled, it will record the binding information
allocated by DHCP Server of all trusted ports. Only after the DHCP SNOOPING function
is enabled, the binding function can be enabled.
Example: Enable the DHCP Snooping binding funciton.
switch(config)#ip dhcp snooping binding enable
Relative Command: ip dhcp snooping enable
5.11 ip dhcp snooping binding arp
Command: ip dhcp snooping binding arp
no ip dhcp snooping binding arp
Function: Enable the DHCP Snooping binding ARP funciton.
Parameters: None
Command Mode: Globe mode
Default Settings: DHCP Snooping binding ARP funciton is disabled by default.
Usage Guide: When this function is enbaled, DHCP SNOOPING will add binding ARP list
entries according to binding information. Only after the binding function is enabled, can
the binding ARP function be enabled. Binding ARP list entries are static entries without
configuration of reservation, and will be added to the NEIGHBOUR list directly. The
priority of binding ARP list entries is lower than the static ARP list entries set by
administrator, so can be overwritten by static ARP list entries; but, when static ARP list
entries are deleted, the binding ARP list entries can not be recovered untill the DHCP
SNOOPING recapture the biding inforamtion. Adding binding ARP list entries is used to
prevent these list entried from being attacked by ARP cheating. At the same time, these
static list entries need no reauthenticaiton, which can prenvent the switch from the
failing to reauthenticate ARP when it is being attacked by ARP scanning.

Содержание

Explore essential commands for configuring DHCP Snooping to enhance network security. Learn how to manage defense actions and enable binding functions effectively.

Скачать