HP 6125XLG R2306-HP 6125XLG Blade Switch Layer 3 - IP Services Configuration G - Page 79

Configuring DHCP packet rate limit, Displaying and maintaining DHCP snooping

Page 79 highlights

compares the entry with the message information. If they are consistent, the message is considered as valid and forwarded to the DHCP server. If they are different, the message is considered as a forged message and is discarded. If no matching entry is found, the message is considered valid and forwarded to the DHCP server. To enable DHCP-REQUEST check: Step 1. Enter system view. 2. Enter interface view. Command system-view interface interface-type interface-number 3. Enable DHCP-REQUEST check. dhcp snooping check request-message Remarks N/A N/A By default, DHCP-REQUEST check is disabled. You can enable DHCP-REQUEST check only on Ethernet interfaces and aggregate interfaces. Configuring DHCP packet rate limit Perform this task to configure the maximum rate at which an interface can receive DHCP packets. This feature discards exceeding DHCP packets to prevent attacks that send large numbers of DHCP packets. To configure DHCP packet rate limit: Step 1. Enter system view. 2. Enter interface view. Command system-view interface interface-type interface-number 3. Configure the maximum rate at which the interface can receive DHCP packets. dhcp snooping rate-limit rate Remarks N/A N/A By default, incoming DHCP packets are not rate limited. You can configure this command only on Ethernet interfaces and aggregate interfaces. If an Ethernet interface belongs to an aggregation group, it uses the DHCP packet maximum rate configured on the corresponding aggregate interface. Displaying and maintaining DHCP snooping Execute display commands in any view, and reset commands in user view. Task Display DHCP snooping entries. Command display dhcp snooping binding [ ip ip-address [ vlan vlan-id ] ] Remarks Available in any view. 70

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230

70
compares the entry with the message information. If they are consistent, the message is considered as
valid and forwarded to the DHCP server. If they are different, the message is considered as a forged
message and is discarded. If no matching entry is found, the message is considered valid and forwarded
to the DHCP server.
To enable DHCP-REQUEST check:
Step
Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enter interface view.
interface
interface-type
interface-number
N/A
3.
Enable DHCP-REQUEST check.
dhcp snooping check
request-message
By default, DHCP-REQUEST check is
disabled.
You can enable DHCP-REQUEST
check only on Ethernet interfaces and
aggregate interfaces.
Configuring DHCP packet rate limit
Perform this task to configure the maximum rate at which an interface can receive DHCP packets. This
feature discards exceeding DHCP packets to prevent attacks that send large numbers of DHCP packets.
To configure DHCP packet rate limit:
Step
Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enter interface view.
interface
interface-type
interface-number
N/A
3.
Configure the maximum rate at
which the interface can receive
DHCP packets.
dhcp snooping rate-limit
rate
By default, incoming DHCP
packets are not rate limited.
You can configure this command
only on Ethernet interfaces and
aggregate interfaces.
If an Ethernet interface belongs to
an aggregation group, it uses the
DHCP packet maximum rate
configured on the corresponding
aggregate interface.
Displaying and maintaining DHCP snooping
Execute
display
commands in any view, and
reset
commands in user view.
Task
Command
Remarks
Display DHCP snooping entries.
display dhcp snooping binding
[
ip
ip-address
[
vlan
vlan-id
] ]
Available in any view.