Port Number Requirements For Dhcp Firewall Filters; Table 9: Unsupported Opaque Dhcp Options - Juniper EX3400 Features Manual

Dhcp and other system services feature guide
Hide thumbs Also See for EX3400:
Table of Contents

Advertisement

DHCP and Other System Services Feature Guide for EX2300, EX3400, and EX4300 Switches
Related
Documentation

Port Number Requirements for DHCP Firewall Filters

36

Table 9: Unsupported Opaque DHCP Options

DHCP Option
Option Name
Option 0
Pad Option
Option 51
IP Address Lease Time
Option 52
Option Overload
Option 53
DHCP Message Type
Option 54
Server Identifier
Option 55
Parameter Request List
Option 255
End
DHCP magic cookie
Monitoring DHCP Options Configured on RADIUS Servers
When you configure a firewall filter to perform some action on DHCP packets at the
Routing Engine, such as protecting the Routing Engine by allowing only proper DHCP
packets, you must specify both port 67 (bootps) and port 68 (bootpc) for both the source
and destination. The firewall filter acts at both the line cards and the Routing Engine.
This requirement applies to both DHCP local server and DHCP relay, but it applies only
when DHCP is provided by the jdhcpd process. MX Series routers use jdhcpd. For DHCP
relay, that means the configuration is required only at the
dhcp-relay]
hierarchy level and not at the
level.
DHCP packets received on the line cards are encapsulated by jdhcpd with a new UDP
header where their source and destination addresses are set to port 68 before being
forwarded to the Routing Engine.
For DHCP relay and DHCP proxy, packets sent to the DHCP server from the router have
both the source and destination UDP ports set to 67. The DHCP server responds using
the same ports. However, when the line card receives these DHCP response packets, it
changes both port numbers from 67 to 68 before passing the packets to the Routing
Engine. Consequently the filter needs to accept port 67 for packets relayed from the
client to the server, and port 68 for packets relayed from the server to the client.
Comments
Not supported.
Value is provided by RADIUS
attribute 27 (Session-Timeout).
Not supported.
Value is provided by DHCP local
server.
Value is provided by DHCP local
server.
Value is provided by DHCP local
server.
Value is provided by DHCP local
server.
Not supported.
[edit forwarding-options
[edit forwarding-options helpers bootp]
Copyright © 2017, Juniper Networks, Inc.
hierarchy

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Ex4300Ex2300

Table of Contents