About DHCP Snooping Configuration

Source: Internet
Author: User

DHCP Snooping plays a critical role in the DHCP protocol. This part is involved in many settings. Now let's take a look at the knowledge of DHCP Snooping configuration. We hope to give everyone a new understanding.

DHCP Server Spoofing

The attacker sets up an illegal DHCP server on the vswitch and sends the IP address to the DHCP server from which the client sends the IP address in the client network. The attacker takes the IP address based on the character) attackers can direct the client's gateway to themselves, so they can get all the data packets from the client, and then relay the data packets to the real gateway, but the client does not feel the same.

Defense methods

Configure DHCP Snooping

Configure ip dhcp Snooping

1. enable DHCP Snooping globally (required)

Ip dhcp snooping

2. Enable on vlan

Ip dhcp snoping vlan 11-200

3. It is an important command to enable DHCP Trust on the interface. By default, after dhcp snooping is enabled globally, all interfaces are untrust and can only be connected to PCs, configure trust under the interface connected to the access layer switch. The untrust interface can only send DHCP requests, and other DHCP-related packets are discarded)

Ip dhcp snooping trust

4. You can configure the dhcp packet rate on the Interface connected to the pc.

Ip dhcp snooping limit rate: 100

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.