1. DHCP snooping parsing
When DHCP snooping is turned on, all ports are untrusted interfaces by default.
Untrusted interface: The discovery message can be received, but when an offer message is received, it is dropped directly and no DHCP message is sent.
Trusted interface: Send and receive any DHCP messages. Generally, the upstream port and the port that connects to the trusted DHCP server are set to the trusted interface.
2. Experimental topology
650) this.width=650; "src=" Http://s5.51cto.com/wyfs02/M02/79/8A/wKioL1aUeYWAnD4eAAA68gB0E7o267.png "title=" d1.png "alt=" Wkiol1aueywand4eaaa68gb0e7o267.png "/>
3. Basic Configuration
IOU3 Configuration
No IP routing
IP DHCP Pool pool3
Network 3.3.3.0 255.255.255.0
Interface ethernet0/0
IP address 3.3.3.3 255.255.255.0
IOU4 Configuration
No IP routing
IP DHCP Pool POOL4
Network 4.4.4.0 255.255.255.0
Interface ethernet0/0
IP address 4.4.4.4 255.255.255.0
IOU5 Configuration
Interface ethernet0/0
IP address DHCP
4. DHCP snooping Configuration
IOU1 Configuration
IP DHCP snooping VLAN 1
IP DHCP snooping
Interface ETHERNET0/1
IP DHCP snooping Trust
IOU3 Configuration
IP DHCP relay information trust-all
IOU4 Configuration
IP DHCP relay information trust-all
650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M00/79/8E/wKiom1aUk-HSIxTmAABJGPo84kg620.png "title=" d2.png "alt=" Wkiom1auk-hsixtmaabjgpo84kg620.png "/>
After configuring DHCP snooping, IOU5 IP is 4.4.4.0 the IP segment of the network multiple times by DHCP.
This article is from the "Open Source Hall" blog, please be sure to keep this source http://kaiyuandiantang.blog.51cto.com/10699754/1734144
88, the switch security Spoofing Attack configuration experiment DHCP snooping