Snooping:嗅探 .窥视
Relay:中继
Client:客户
hardware:硬件
address:地址
trusted:信任
untrsted:不信任
check:检查
DHCP snooping:DHCP 嗅探
sticky:粘性
一 . 交换机部署DHCP
测试环境:
配置DHCP服务器:
[SW1-dhcp]vlan batch 10 20
Info: This operation may take a few seconds. Please wait for a moment...done.
[SW1-dhcp]dhcp enable
Info: The operation may take a few seconds. Please wait for a moment.done.
[SW1-dhcp]port-g
[SW1-dhcp]port-group g
[SW1-dhcp]port-group group-member g 0/0/1 g 0/0/2
[SW1-dhcp-port-group]port l
[SW1-dhcp-port-group]port link-t
[SW1-dhcp-port-group]port link-type t
[SW1-dhcp-port-group]port link-type trunk
[SW1-dhcp-GigabitEthernet0/0/1]port link-type trunk
[SW1-dhcp-GigabitEthernet0/0/2]port link-type trunk
[SW1-dhcp-port-group]p t a v a
[SW1-dhcp-GigabitEthernet0/0/1]p t a v a
[SW1-dhcp-GigabitEthernet0/0/2]p t a v a
[SW1-dhcp-port-group]q
[SW1-dhcp]ip pool vlan 10
^
Error:Too many parameters found at '^' position.
[SW1-dhcp]ip pool vlan10
Info:It's successful to create an IP address pool.
[SW1-dhcp-ip-pool-vlan10]network 192.168.10.0 mask 24
[SW1-dhcp-ip-pool-vlan10]gateway-
[SW1-dhcp-ip-pool-vlan10]gateway-list 192.168.10.254
[SW1-dhcp-ip-pool-vlan10]dns
[SW1-dhcp-ip-pool-vlan10]dns-list 8.8.8.8
[SW1-dhcp-ip-pool-vlan10]ip add
[SW1-dhcp-ip-pool-vlan10]ip pool vlan20
Info:It's successful to create an IP address pool.
[SW1-dhcp-ip-pool-vlan20]net
[SW1-dhcp-ip-pool-vlan20]network 192.168.20.0 mask 24
[SW1-dhcp-ip-pool-vlan20]g
[SW1-dhcp-ip-pool-vlan20]gateway-list 192.168.20.254
[SW1-dhcp-ip-pool-vlan20]d
[SW1-dhcp-ip-pool-vlan20]dns-list 8.8.8.8
[SW1-dhcp-ip-pool-vlan20]q
[SW1-dhcp]int v10
[SW1-dhcp-Vlanif10]ip add
[SW1-dhcp-Vlanif10]ip address 192.168.10.254 24
[SW1-dhcp-Vlanif10]d
[SW1-dhcp-Vlanif10]dhcp s
[SW1-dhcp-Vlanif10]dhcp sel
[SW1-dhcp-Vlanif10]dhcp select g
[SW1-dhcp-Vlanif10]dhcp select global
[SW1-dhcp-Vlanif10]int v20
[SW1-dhcp-Vlanif20]ip a
[SW1-dhcp-Vlanif20]ip address 192.168.20.254 24
[SW1-dhcp-Vlanif20]dhcp sel
[SW1-dhcp-Vlanif20]dhcp select g
[SW1-dhcp-Vlanif20]dhcp select global
[SW1-dhcp-Vlanif20]
<Sw2>system-view
Enter system view, return user view with Ctrl+Z.
[Sw2]vlan b
[Sw2]vlan batch 10 20
Info: This operation may take a few seconds. Please wait for a moment...done.
[Sw2]int g 0/0/1
[Sw2-GigabitEthernet0/0/1]port l
[Sw2-GigabitEthernet0/0/1]port link-t
[Sw2-GigabitEthernet0/0/1]port link-type t
[Sw2-GigabitEthernet0/0/1]port link-type trunk
[Sw2-GigabitEthernet0/0/1]port t
[Sw2-GigabitEthernet0/0/1]port trunk allow-pass all
^
Error: Unrecognized command found at '^' position.
[Sw2-GigabitEthernet0/0/1]q
[Sw2]port-g
[Sw2]port-group g
[Sw2]port-group group-member g0/0/2 g0/0/3
[Sw2-port-group]p l a
[Sw2-GigabitEthernet0/0/2]p l a
[Sw2-GigabitEthernet0/0/3]p l a
[Sw2-port-group]p d v 10
[Sw2-GigabitEthernet0/0/2]p d v 10
[Sw2-GigabitEthernet0/0/3]p d v 10
<SW3>system-view
Enter system view, return user view with Ctrl+Z.
[SW3]vlan b
[SW3]vlan batch 10 20
Info: This operation may take a few seconds. Please wait for a moment...done.
[SW3]int g0/0/1
[SW3-GigabitEthernet0/0/1]p l t
[SW3-GigabitEthernet0/0/1]p t a v a
[SW3-GigabitEthernet0/0/1]q
[SW3]port-g
[SW3]port-group g
[SW3]port-group group-member g0/0/2 g0/0/3
[SW3-port-group]p l a
[SW3-GigabitEthernet0/0/2]p l a
[SW3-GigabitEthernet0/0/3]p l a
[SW3-port-group]p d v 20
[SW3-GigabitEthernet0/0/2]p d v 20
[SW3-GigabitEthernet0/0/3]p d v 20
[SW3-port-group]
验证:
二 . DHCP Server仿冒者攻击实验
配置仿冒DHCP服务器
<Huawei>system-view
Enter system view, return user view with Ctrl+Z.
[Huawei]sy SW3-fm
[SW3-fm]dhcp enable
Info: The operation may take a few seconds. Please wait for a moment.done.
[SW3-fm]ip pool v 1
^
Error:Too many parameters found at '^' position.
[SW3-fm]ip pool v1
Info:It's successful to create an IP address pool.
[SW3-fm-ip-pool-v1]network 192.168.10.0 mask 24
[SW3-fm-ip-pool-v1]gateway-l
[SW3-fm-ip-pool-v1]gateway-list 192.168.10.254
[SW3-fm-ip-pool-v1]dns-l
[SW3-fm-ip-pool-v1]dns-list 9.9.9.9
[SW3-fm-ip-pool-v1]q
配置合法DHCP服务器
[SW2-hf]sy SW2-dhcp
[SW2-dhcp]dhcp enable
Info: The operation may take a few seconds. Please wait for a moment.done.
[SW2-dhcp]ip pool v1
Info:It's successful to create an IP address pool.
[SW2-dhcp-ip-pool-v1]network 192.168.15.0 mask 24
[SW2-dhcp-ip-pool-v1]gat
[SW2-dhcp-ip-pool-v1]gateway-list 192.168.15.254
[SW2-dhcp-ip-pool-v1]dns-
[SW2-dhcp-ip-pool-v1]dns-list 8.8.8.8
[SW2-dhcp-ip-pool-v1]q
[SW2-dhcp]int v1
[SW2-dhcp-Vlanif1]ip add
[SW2-dhcp-Vlanif1]ip address 192.168.15.254 24
[SW2-dhcp-Vlanif1]dhcp sel
[SW2-dhcp-Vlanif1]dhcp select g
[SW2-dhcp-Vlanif1]dhcp select global
[SW2-dhcp-Vlanif1]
验证:
在SW1上配置DHCP Snooping
<Huawei>u t m
Info: Current terminal monitor is off.
<Huawei>sy
<Huawei>system-view
Enter system view, return user view with Ctrl+Z.
[Huawei]sy Sw1
[Sw1]dhcp enable
Info: The operation may take a few seconds. Please wait for a moment.done.
[Sw1]dhcp snoo
[Sw1]dhcp snooping enable
[Sw1]port-g
[Sw1]port-group g
[Sw1]port-group group-member g0/0/1 g0/0/2
[Sw1-port-group]dhcp sn
[Sw1-port-group]dhcp snooping e
[Sw1-port-group]dhcp snooping enable
[Sw1-GigabitEthernet0/0/1]dhcp snooping enable
[Sw1-GigabitEthernet0/0/2]dhcp snooping enable
[Sw1-port-group]q
[Sw1]int g0/0/4
[Sw1-GigabitEthernet0/0/4]dhcp sn
[Sw1-GigabitEthernet0/0/4]dhcp snooping ?
alarm Alarm
check Check
disable Disable
enable Enable
max-user-number Max user number
sticky-mac DHCP snooping sticky mac
trusted Trusted interface
[Sw1-GigabitEthernet0/0/4]dhcp snooping tr
[Sw1-GigabitEthernet0/0/4]dhcp snooping trusted
[Sw1-GigabitEthernet0/0/4]
验证: