2-6
To improve security and avoid malicious attack to the unused SOCKETs, S5500-EI Ethernet switches
provide the following functions:
z
UDP 67 and UDP 68 ports used by DHCP are enabled only when DHCP is enabled.
z
UDP 67 and UDP 68 ports are disabled when DHCP is disabled.
The corresponding implementation is as follows.
z
When a VLAN interface is mapped to a DHCP server group with the
dhcp-server
command, the
DHCP relay agent is enabled. At the same time, UDP 67 and UDP 68 ports used by DHCP are
enabled.
z
When the mapping between a VLAN interface and a DHCP server group is removed with the
undo
dhcp-server
command, DHCP services are disabled. At the same time, UDP 67 and UDP 68
ports used by DHCP are disabled.
Examples
# Enter system view.
<Sysname> system-view
System View: return to User View with Ctrl+Z.
# Enter VLAN-interface 1 view.
[Sysname] interface vlan-interface 1
# Specify that VLAN-interface 1 corresponds to DHCP server group 1.
[Sysname-Vlan-interface1] dhcp-server 1
dhcp-server detect
Syntax
dhcp-server detect
undo dhcp-server detect
View
System view
Parameters
None
Description
Use the
dhcp-server detect
command to enable the switch serving as a DHCP relay agent to detect
unauthorized DHCP servers.
Use the
undo dhcp-server detect
command to disable the unauthorized DHCP server detection
function.
By default, the unauthorized DHCP server detection function is disabled
Related commands:
dhcp server
,
display dhcp-server
.
Summary of Contents for 5500-EI PWR
Page 43: ...2 6...
Page 76: ...1 17...
Page 228: ...ii stp transmit limit 1 44 vlan mapping modulo 1 45 vlan vpn tunnel 1 46...
Page 477: ...5 24 Sysname vlan 2 Sysname vlan2 service type multicast...
Page 503: ...2 3 System View return to User View with Ctrl Z Sysname dot1x url http 192 168 19 23...
Page 519: ...iii...
Page 597: ...2 2 security policy server 192 168 0 1 user name format without domain...
Page 648: ...1 9 Examples Clear static ARP entries Sysname reset arp static...
Page 663: ...4 3 Sysname resilient arp interface vlan interface 2...
Page 767: ...1 28 From 12 00 Jan 1 2008 to 12 00 Jun 1 2008...
Page 1111: ...ii xmodem get 3 18...
Page 1314: ...A 44 Z...