Setting The Maximum Number Of Dhcp Snooping Entries; Configuring Dhcp Packet Rate Limit - HP 6125XLG Layer 3-Ip Services Configuration Manual

Blade switch
Table of Contents

Advertisement

Attackers can forge DHCP lease renewal packets to renew leases for legitimate DHCP clients that no
longer need the IP addresses. These forged messages disable the victim DHCP server from releasing the
IP addresses.
Attackers can also forge DHCP-DECLINE or DHCP-RELEASE packets to terminate leases for legitimate
DHCP clients that still need the IP addresses.
To prevent such attacks, you can enable DHCP-REQUEST check. This feature uses DHCP snooping entries
to check incoming DHCP-REQUEST messages. If a matching entry is found for a message, this feature
compares the entry with the message information. If they are consistent, the message is considered as
valid and forwarded to the DHCP server. If they are different, the message is considered as a forged
message and is discarded. If no matching entry is found, the message is considered valid and forwarded
to the DHCP server.
To enable DHCP-REQUEST check:
Step
1.
Enter system view.
2.
Enter interface view.
3.
Enable DHCP-REQUEST check.
Setting the maximum number of DHCP snooping
entries
Perform this task to prevent the system resources from being overused.
To set the maximum number of DHCP snooping entries:
Step
1.
Enter system view.
2.
Enter interface view.
3.
Set the maximum number of
DHCP snooping entries for the
interface to learn.

Configuring DHCP packet rate limit

Perform this task to configure the maximum rate at which an interface can receive DHCP packets. This
feature discards exceeding DHCP packets to prevent attacks that send large numbers of DHCP packets.
To configure DHCP packet rate limit:
Command
system-view
interface interface-type
interface-number
dhcp snooping check
request-message
Command
system-view
interface interface-type
interface-number
dhcp snooping max-learning-num
number
75
Remarks
N/A
N/A
By default, DHCP-REQUEST
check is disabled.
You can enable DHCP-REQUEST
check only on Layer 2 Ethernet
interfaces and Layer 2 aggregate
interfaces.
Remarks
N/A
N/A
By default, the number of DHCP
snooping entries for an interface to
learn is not limited.

Advertisement

Table of Contents
loading

Table of Contents