Configuring Dhcp Security Features; Using The Relay Agent Information Option (Option-82) - Alcatel-Lucent OmniSwitch 6850-48 Network Configuration Manual

Software release 6
Hide thumbs Also See for OmniSwitch 6850-48:
Table of Contents

Advertisement

Configuring DHCP Relay

Configuring DHCP Security Features

There are two DHCP security features available: DHCP relay agent information option (Option-82) and
DHCP Snooping. The DHCP Option-82 feature enables the relay agent to insert identifying information
into client-originated DHCP packets before the packets are forwarded to the DHCP server. The DHCP
Snooping feature filters DHCP packets between untrusted sources and a trusted DHCP server and builds a
binding database to log DHCP client information.
Although DHCP Option-82 is a subcomponent of DHCP Snooping, these two features are mutually exclu-
sive. If the DHCP Option-82 feature is enabled for the switch, then DHCP Snooping is not available. The
reverse is also true; if DHCP Snooping is enabled, then DHCP Option-82 is not available. In addition, the
following differences exist between these two features:
DHCP Snooping does require and use the Option-82 data insertion capability, but does not implement
any other behaviors defined in RFC 3046.
DHCP Snooping is configurable at the switch level and on a per-VLAN basis, but DHCP Option-82 is
only configurable at the switch level.
The following sections provide additional information about each DHCP security feature and how to
configure feature parameters using the Command Line Interface (CLI).

Using the Relay Agent Information Option (Option-82)

This implementation of the DHCP relay agent information option (Option-82) feature is based on the
functionality defined in RFC 3046. By default DHCP Option-82 functionality is disabled. The
agent-information
command is used to enable this feature at the switch level.
When this feature is enabled, communications between a DHCP client and a DHCP server are authenti-
cated by the relay agent. To accomplish this task, the agent adds Option-82 data to the end of the options
field in DHCP packets sent from a client to a DHCP server. Option-82 consists of two suboptions: Circuit
ID and Remote ID. The agent fills in the following information by default for each of these suboptions:
Circuit ID—the VLAN ID and slot/port from where the DHCP packet originated.
Remote ID—the MAC address of the router interface associated with the VLAN ID specified in the
Circuit ID suboption.
The
ip helper dhcp-snooping option-82 format
MAC address, system name, interface alias, or user-defined) that is inserted into the above Option-82
suboptions. The system name and user-defined text are reported in ASCII text format, but the MAC
address is still reported in hex-based format.
By default, the relay agent drops client DHCP packets it receives that already contain Option-82 data.
However, it is possible to configure an Option-82 policy to specify how such packets are treated. See
"Configuring a Relay Agent Information Option-82 Policy" on page 31-17
The DHCP Option-82 feature is only applicable when DHCP relay is used to forward DHCP packets
between clients and servers associated with different VLANs. In addition, a secure IP network must exist
between the relay agent and the DHCP server.
OmniSwitch AOS Release 6 Network Configuration Guide
Configuring DHCP Security Features
command is used to configure the type of data (base
September 2009
ip helper
for more information.
page 31-15

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents