Zyxel Switch-How to block a fake DHCP server without enabling DHCP snooping?
2016-08-09 15:45
323 查看
How to block a fake DHCP server without enabling DHCP snooping?
Scenario
How to block a fake DHCP server without enabling DHCP snooping and still fulfill the following requirements?1. The trusted DHCP server is connected on port 40.
2. Block the fake DHCP server from other ports.
Step
Without enabling the DHCP snooping feature, we can use the ACL feature to fulfill the above requirement.Please configure the following classifiers and policy rules for the switch with CLI commands.
Classifier
classifier "block DHCP" ethernet-type ip ip-protocol udp source-socket 67 destination-socket 68
=> To block DHCP server from all ports.
classifier "allow DHCP" ethernet-type ip source-port 40 ip-protocol udp source-socket 67 destination-socket 68
=> To allow Trusted DHCP server from the specific port 40.
Policy Rule
policy allow classifier "allow DHCP" egress-port 1 priority 0 dscp 0 tos 0 bandwidth 0 out-of-profile-dscp 0
=> Select classifier-block DHCP, action: drop packets.
policy block classifier "block DHCP" egress-port 1 priority 0 dscp 0 tos 0 bandwidth 0 out-of-profile-dscp 0 forward-action drop
=> Select classifier-allow DHCP, action: forward packets.
Verification
Connect the trusted DHCP server on port 40 and the PC on port 10.The PC can receive the IP address successfully.
However, if you connect other DHCP servers to other ports and port 40 is disconnected, the PC on port 10 will be unable to get any IP address.
相关文章推荐
- How to hot add lun to Linux server without rebooting
- How to Create a SharePoint 2010 Project Without SharePoint Server
- How to install DHCP server on Windows Server 2008R2
- How to build DHCP&NTP server on Linux(Ubuntu)
- How to Clear the Application Server Cache Without Shutting it Down
- How to CORS enable ArcGIS Server 10.2.1 to Access REST Services without Using proxy.ashx
- How to Create a SharePoint 2010 Project Without SharePoint Server
- How to allow/block PING on Linux server – IPTables rules for icmp---reference
- How to delete duplicate rows without children in sql server
- How to build DHCP&NTP server on Linux(Ubuntu)
- Howto change runtime variables without restart MySQL Server
- how to remote connect to isa server 2000?
- How to determine which version of SQL Server 2000 is running
- How to freeze a dynamic aspx page into a static html page (on the server).(转:http://codebetter.com/blogs/peter.van.ooijen/archiv
- How to migrate DTS package from Server A to Server B
- illustrates how to call a SQL Server stored procedure
- How to install Mysql in linux server
- how to set onclick event priority on both client & server
- How to reset the Domain Admin Password under Windows Server 2003
- How to use sendmail to configure SMTP server