The configured trusted or untrusted interface records a maximum of 64 logs about the DHCP server. When 64 logs are generated on the interface, the later logs override the previous ones. In addition, the aging time of logs is 24 hours.
The DHCP snooping function must have been globally enabled.
An attacker pretends to be a DHCP server and replies to a DHCP client with an incorrect gateway address, DNS server address, and IP address to prevent the client from accessing networks.
Configure GE 0/1/0 as the trusted interface.
<HUAWEI> system-view [~HUAWEI] interface gigabitethernet0/1/0 [~HUAWEI-Gigabitethernet0/1/0] dhcp snooping trusted [*HUAWEI-Gigabitethernet0/1/0] commit
Configure the interface closest to the DHCP server as the trusted interface.