一、dhcp
测试环境:
[Huawei]sysn dhcp
[dhcp]vlan batch 10 20
Info: This operation may take a few seconds. Please wait for a moment...done.
[dhcp]dhcp en
[dhcp]dhcp enable
Info: The operation may take a few seconds. Please wait for a moment.done.
[dhcp]port-group group-member g0/0/1 g0/0/2
[dhcp-port-group]port link-type trunk
[dhcp-GigabitEthernet0/0/1]port link-type trunk
[dhcp-GigabitEthernet0/0/2]port link-type trunk
[dhcp-GigabitEthernet0/0/1]port trunk allow-pass vlan all
[dhcp-GigabitEthernet0/0/2]port trunk allow-pass vlan all
[dhcp-port-group]q
[dhcp]ip pool vlan10
Info:It's successful to create an IP address pool.
[dhcp-ip-pool-vlan10]network 192.168.10.0 mask 24
[dhcp-ip-pool-vlan10]gateway-list 192.168.10.254
[dhcp-ip-pool-vlan10]dns-list 8.8.8.8
[dhcp-ip-pool-vlan10]q
[dhcp]ip pool vlan20
Info:It's successful to create an IP address pool.
[dhcp-ip-pool-vlan20]network 192.168.20.0 mask 24
[dhcp-ip-pool-vlan20]gateway-list 192.168.20.254
[dhcp-ip-pool-vlan20]dns-list 8.8.8.8
[dhcp-ip-pool-vlan20]q
[dhcp]interface Vlanif10
[dhcp-Vlanif10]ip address 192.168.10.254 24
[dhcp-Vlanif10]q
[dhcp]interface Vlanif10
[dhcp-Vlanif10]dhcp select global
[dhcp-Vlanif10]q
[dhcp]interface vlanif 20
[dhcp-Vlanif20]ip address 192.168.20.254 24
[dhcp-Vlanif20]dhcp select global
[s1]vlan 10
[s1-vlan10]q
[s1]port-g
[s1]port-group g
[s1]port-group group-member g0/0/2 g0/0/3
[s1-port-group]port link
[s1-port-group]port link-y
[s1-port-group]port link-yy
[s1-port-group]port link-yu
[s1-port-group]port link-ty
[s1-port-group]port link-type acc
[s1-port-group]port link-type access
[s1-GigabitEthernet0/0/2]port link-type access
[s1-GigabitEthernet0/0/3]port link-type access
[s1-port-group]port
[s1-port-group]port de
[s1-port-group]port default vlan 10
[s1-GigabitEthernet0/0/2]port default vlan 10
[s1-GigabitEthernet0/0/3]port default vlan 10
[s1-port-group]q
[s1]vlan 20
[s1-vlan20]q
[s1]int
[s1]interface g
[s1]interface GigabitEthernet 0/0/1
[s1-GigabitEthernet0/0/1]port link
[s1-GigabitEthernet0/0/1]port link-ty
[s1-GigabitEthernet0/0/1]port link-type t
[s1-GigabitEthernet0/0/1]port link-type trunk
[s1-GigabitEthernet0/0/1]port
[s1-GigabitEthernet0/0/1]port t
[s1-GigabitEthernet0/0/1]port trunk all
[s1-GigabitEthernet0/0/1]port trunk allow-pass vlan all
[Huawei]sysn s2
[s2]port-g
[s2]port-group g
[s2]vlan ba
[s2]vlan batch 10 20
Info: This operation may take a few seconds. Please wait for a moment...done.
[s2]port-g
[s2]port-group g
[s2]port-group group-member g0/0/2 g0/0/3
[s2-port-group]port lin
[s2-port-group]port link-ty
[s2-port-group]port link-type acc
[s2-port-group]port link-type access
[s2-GigabitEthernet0/0/2]port link-type access
[s2-GigabitEthernet0/0/3]port link-type access
[s2-port-group]port de
[s2-port-group]port default vlan 20
[s2-GigabitEthernet0/0/2]port default vlan 20
[s2-GigabitEthernet0/0/3]port default vlan 20
[s2-port-group]q
[s2]int
[s2]interface g
[s2]interface GigabitEthernet 0/0/1
[s2-GigabitEthernet0/0/1]port lin
[s2-GigabitEthernet0/0/1]port link-y
[s2-GigabitEthernet0/0/1]port link-ty
[s2-GigabitEthernet0/0/1]port link-type t
[s2-GigabitEthernet0/0/1]port link-type trunk
[s2-GigabitEthernet0/0/1]port
[s2-GigabitEthernet0/0/1]port t
[s2-GigabitEthernet0/0/1]port trunk all
[s2-GigabitEthernet0/0/1]port trunk allow-pass vlan all
二、DHCP仿冒攻击
测试环境:
[Huawei]dhcp en
[Huawei]dhcp enable
Info: The operation may take a few seconds. Please wait for a moment.done.
[Huawei]dhcp son
[Huawei]dhcp sn
[Huawei]dhcp snooping en
[Huawei]dhcp snooping enable
[Huawei]port-g
[Huawei]port-group g
[Huawei]port-group group-member g0/0/1 g0/0/2
[Huawei-port-group]dhcp sno
[Huawei-port-group]dhcp snooping en
[Huawei-port-group]dhcp snooping enable
[Huawei-GigabitEthernet0/0/1]dhcp snooping enable
[Huawei-GigabitEthernet0/0/2]dhcp snooping enable
[Huawei-port-group]q
[Huawei]int
[Huawei]interface g
[Huawei]interface GigabitEthernet 0/0/4
[Huawei-GigabitEthernet0/0/4]dhcp sn
[Huawei-GigabitEthernet0/0/4]dhcp snooping tru
[Huawei-GigabitEthernet0/0/4]dhcp snooping trusted
三、端口安全