交换机配置dhcp snooping 端口安全

文章介绍了如何在交换机上部署DHCP服务,包括创建IP地址池、配置端口和VLAN。同时,文章通过实验展示了DHCPServer仿冒者攻击,以及如何在SW1上配置DHCP嗅探以增强网络安全,特别是启用DHCPsnooping信任接口来防止未授权的DHCP服务器。

摘要生成于 C知道 ,由 DeepSeek-R1 满血版支持, 前往体验 >

Snooping:嗅探 .窥视

Relay:中继

Client:客户

hardware:硬件

address:地址

trusted:信任

untrsted:不信任

check:检查

DHCP snooping:DHCP 嗅探

sticky:粘性

一 . 交换机部署DHCP

测试环境:

 配置DHCP服务器:

[SW1-dhcp]vlan batch 10 20
Info: This operation may take a few seconds. Please wait for a moment...done.
[SW1-dhcp]dhcp enable
Info: The operation may take a few seconds. Please wait for a moment.done.
[SW1-dhcp]port-g    
[SW1-dhcp]port-group g    
[SW1-dhcp]port-group group-member g 0/0/1 g 0/0/2
[SW1-dhcp-port-group]port l    
[SW1-dhcp-port-group]port link-t    
[SW1-dhcp-port-group]port link-type t    
[SW1-dhcp-port-group]port link-type trunk 
[SW1-dhcp-GigabitEthernet0/0/1]port link-type trunk 
[SW1-dhcp-GigabitEthernet0/0/2]port link-type trunk 
[SW1-dhcp-port-group]p t a v a
[SW1-dhcp-GigabitEthernet0/0/1]p t a v a
[SW1-dhcp-GigabitEthernet0/0/2]p t a v a
[SW1-dhcp-port-group]q
[SW1-dhcp]ip pool vlan 10
                       ^
Error:Too many parameters found at '^' position.
[SW1-dhcp]ip pool vlan10
Info:It's successful to create an IP address pool.
[SW1-dhcp-ip-pool-vlan10]network 192.168.10.0 mask 24
[SW1-dhcp-ip-pool-vlan10]gateway-    
[SW1-dhcp-ip-pool-vlan10]gateway-list 192.168.10.254
[SW1-dhcp-ip-pool-vlan10]dns    
[SW1-dhcp-ip-pool-vlan10]dns-list 8.8.8.8
[SW1-dhcp-ip-pool-vlan10]ip add    
[SW1-dhcp-ip-pool-vlan10]ip pool vlan20
Info:It's successful to create an IP address pool.
[SW1-dhcp-ip-pool-vlan20]net    
[SW1-dhcp-ip-pool-vlan20]network 192.168.20.0 mask 24
[SW1-dhcp-ip-pool-vlan20]g    
[SW1-dhcp-ip-pool-vlan20]gateway-list 192.168.20.254
[SW1-dhcp-ip-pool-vlan20]d    
[SW1-dhcp-ip-pool-vlan20]dns-list 8.8.8.8
[SW1-dhcp-ip-pool-vlan20]q
[SW1-dhcp]int v10
[SW1-dhcp-Vlanif10]ip add    
[SW1-dhcp-Vlanif10]ip address 192.168.10.254 24
[SW1-dhcp-Vlanif10]d    
[SW1-dhcp-Vlanif10]dhcp s    
[SW1-dhcp-Vlanif10]dhcp sel    
[SW1-dhcp-Vlanif10]dhcp select g    
[SW1-dhcp-Vlanif10]dhcp select global 
[SW1-dhcp-Vlanif10]int v20
[SW1-dhcp-Vlanif20]ip a    
[SW1-dhcp-Vlanif20]ip address 192.168.20.254 24
[SW1-dhcp-Vlanif20]dhcp sel    
[SW1-dhcp-Vlanif20]dhcp select  g    
[SW1-dhcp-Vlanif20]dhcp select  global 
[SW1-dhcp-Vlanif20]
 

<Sw2>system-view 
Enter system view, return user view with Ctrl+Z.
[Sw2]vlan b    
[Sw2]vlan batch 10 20
Info: This operation may take a few seconds. Please wait for a moment...done.
[Sw2]int g 0/0/1
[Sw2-GigabitEthernet0/0/1]port l    
[Sw2-GigabitEthernet0/0/1]port link-t    
[Sw2-GigabitEthernet0/0/1]port link-type t    
[Sw2-GigabitEthernet0/0/1]port link-type trunk 
[Sw2-GigabitEthernet0/0/1]port t    
[Sw2-GigabitEthernet0/0/1]port trunk allow-pass all
                                                ^
Error: Unrecognized command found at '^' position.
[Sw2-GigabitEthernet0/0/1]q
[Sw2]port-g    
[Sw2]port-group g    
[Sw2]port-group group-member  g0/0/2 g0/0/3
[Sw2-port-group]p l a
[Sw2-GigabitEthernet0/0/2]p l a
[Sw2-GigabitEthernet0/0/3]p l a
[Sw2-port-group]p d v 10
[Sw2-GigabitEthernet0/0/2]p d v 10
[Sw2-GigabitEthernet0/0/3]p d v 10
 

<SW3>system-view 
Enter system view, return user view with Ctrl+Z.
[SW3]vlan b    
[SW3]vlan batch 10 20
Info: This operation may take a few seconds. Please wait for a moment...done.
[SW3]int g0/0/1
[SW3-GigabitEthernet0/0/1]p l t
[SW3-GigabitEthernet0/0/1]p t a v a
[SW3-GigabitEthernet0/0/1]q
[SW3]port-g    
[SW3]port-group g    
[SW3]port-group group-member g0/0/2 g0/0/3
[SW3-port-group]p l a
[SW3-GigabitEthernet0/0/2]p l a
[SW3-GigabitEthernet0/0/3]p l a
[SW3-port-group]p d v 20
[SW3-GigabitEthernet0/0/2]p d v 20
[SW3-GigabitEthernet0/0/3]p d v 20
[SW3-port-group]
 

验证:

 

二 . DHCP Server仿冒者攻击实验

 

配置仿冒DHCP服务器

<Huawei>system-view 
Enter system view, return user view with Ctrl+Z.
[Huawei]sy SW3-fm
[SW3-fm]dhcp enable
Info: The operation may take a few seconds. Please wait for a moment.done.
[SW3-fm]ip pool v 1
                  ^
Error:Too many parameters found at '^' position.
[SW3-fm]ip pool v1
Info:It's successful to create an IP address pool.
[SW3-fm-ip-pool-v1]network 192.168.10.0 mask 24
[SW3-fm-ip-pool-v1]gateway-l    
[SW3-fm-ip-pool-v1]gateway-list 192.168.10.254
[SW3-fm-ip-pool-v1]dns-l    
[SW3-fm-ip-pool-v1]dns-list 9.9.9.9
[SW3-fm-ip-pool-v1]q
 

配置合法DHCP服务器

[SW2-hf]sy SW2-dhcp
[SW2-dhcp]dhcp enable
Info: The operation may take a few seconds. Please wait for a moment.done.
[SW2-dhcp]ip pool v1
Info:It's successful to create an IP address pool.
[SW2-dhcp-ip-pool-v1]network 192.168.15.0 mask 24
[SW2-dhcp-ip-pool-v1]gat    
[SW2-dhcp-ip-pool-v1]gateway-list 192.168.15.254
[SW2-dhcp-ip-pool-v1]dns-    
[SW2-dhcp-ip-pool-v1]dns-list 8.8.8.8
[SW2-dhcp-ip-pool-v1]q
[SW2-dhcp]int v1
[SW2-dhcp-Vlanif1]ip add    
[SW2-dhcp-Vlanif1]ip address 192.168.15.254 24
[SW2-dhcp-Vlanif1]dhcp sel    
[SW2-dhcp-Vlanif1]dhcp select g    
[SW2-dhcp-Vlanif1]dhcp select global 
[SW2-dhcp-Vlanif1]

验证:

 

 在SW1上配置DHCP Snooping

<Huawei>u t m
Info: Current terminal monitor is off.
<Huawei>sy    
<Huawei>system-view 
Enter system view, return user view with Ctrl+Z.
[Huawei]sy Sw1
[Sw1]dhcp enable
Info: The operation may take a few seconds. Please wait for a moment.done.
[Sw1]dhcp snoo    
[Sw1]dhcp snooping enable
[Sw1]port-g    
[Sw1]port-group g    
[Sw1]port-group group-member g0/0/1 g0/0/2
[Sw1-port-group]dhcp sn    
[Sw1-port-group]dhcp snooping e    
[Sw1-port-group]dhcp snooping enable 
[Sw1-GigabitEthernet0/0/1]dhcp snooping enable 
[Sw1-GigabitEthernet0/0/2]dhcp snooping enable 
[Sw1-port-group]q
[Sw1]int g0/0/4
[Sw1-GigabitEthernet0/0/4]dhcp sn    
[Sw1-GigabitEthernet0/0/4]dhcp snooping ?
  alarm            Alarm 
  check            Check 
  disable          Disable
  enable           Enable 
  max-user-number  Max user number
  sticky-mac       DHCP snooping sticky mac 
  trusted          Trusted interface 

[Sw1-GigabitEthernet0/0/4]dhcp snooping tr    
[Sw1-GigabitEthernet0/0/4]dhcp snooping trusted 
[Sw1-GigabitEthernet0/0/4]

验证:

 

评论 1
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值