Chapter 32 Dhcpv6 Snooping Configuration; Introduction To Dhcpv6 Snooping; Defense Against Fake Dhcpv6 Server; Defense Against Fake Ipv6 Address - Planet XGS3-42000R User Manual

4-slot layer 3 ipv6/ ipv4 routing chassis switch
Table of Contents

Advertisement

Chapter 32 DHCPv6 Snooping Configuration

32.1 Introduction to DHCPv6 Snooping

DHCP v6 Snooping monitors the interaction flow of the packets between DHCP v6 client and server, so as to
create the binding table of the user, and implement all kinds of security policies based on the binding table.
DHCP v6 Snooping has the following functions:

32.1.1 Defense against Fake DHCPv6 Server

DHCP v6 Snooping can set the port of connecting DHCP v6 server as the trust port, other ports as the
un-trusted ports by default, so as to avoid the user to configure DHCP v6 server privat ely in network. DHCP v6
Snooping does not forward DHCP v6 response packets which are received by the un-trusted ports, and
according to the source MAC of the received DHCP v6 response packets to implement the security policy. For
example, this MAC is set as a blackhole MAC wit hin a period, or this port is directly shutdown within a period.

32.1.2 Defense against Fake IPv6 Address

DHCP v6 Snooping function can send the cont rol list entries based the binding on the port. The port denies all
IP v6 traffic by default, it only allows to forward IP v6 packets of which the IP v6 addresses and the MA C
addresses are bound by this port as the source. In this way, it can effectively prevent the malicious user fake
or privat ely set IP v6 address to access the network.
32.1.3 Defense against the attack of DHCPv6 addresses
exhaustion
DHCP v6 Snooping can limit the binding number of the port. The port of which the binding number exceeds
the threshold, does not forward and drop the after DHCP v6 application packets. In this way, it can effectively
prevent the attack of DHCP v6 addresses exhaustion.

32.1.4 Defense against ND cheat

The IP v6 address obtained by DHCP v6 protocol can be trustier in IP v6 net work, so DHCP v6 Snooping can
convert the binding list entries to static one, and effectively prevent the attack of ND cheat to a gateway device.
The function of binding ND for DHCP v6 Snooping needs to be enabled on the devic e of lay er 3 gateway.
32-1

Advertisement

Table of Contents

Troubleshooting

loading

Table of Contents