Preventing The Bogus Dhcp Server Attack; Establishing The Configuration Task - Huawei Quidway S3700 Series Configuration Manual

Hide thumbs Also See for Quidway S3700 Series:
Table of Contents

Advertisement

Quidway S3700 Series Ethernet Switches
Configuration Guide - Security
Type of Attacks
Attack by sending bogus messages to
extend IP address leases
DHCP flooding attack

3.3 Preventing the Bogus DHCP Server Attack

To prevent the attack from the pseudo DHCP server, use the trusted/untrusted working mode of
DHCP snooping.

3.3.1 Establishing the Configuration Task

Establishing the Configuration Task of Preventing the Bogus DHCP Server Attack.
Applicable Environment
When a bogus DHCP server exists on a network, the bogus DHCP server on the network replies
with incorrect messages such as the incorrect IP address of the gateway, incorrect domain name
server (DNS) server, and incorrect IP address to the DHCP client. As a result, the DHCP client
cannot access the network or cannot access the correct destination network.
To prevent a bogus DHCP server attack, you can configure DHCP snooping on the S3700,
configure the network-side interface to be trusted and the user-side interface to be untrusted, and
discard DHCP Reply messages received from untrusted interfaces.
To locate a bogus DHCP server, you can configure detection of bogus DHCP servers on the
S3700. In this case, the S3700 obtains related information about DHCP servers by checking
DHCP Reply messages, and records the information in the log. This facilitates network
maintenance.
Pre-configuration Tasks
Before preventing the bogus DHCP server attack, complete the following tasks:
l
Data Preparation
To prevent the bogus DHCP server attack, you need the following data.
No.
1
Issue 01 (2011-07-15)
Configuring the DHCP server
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
3 DHCP Snooping Configuration
DHCP Snooping Operation Mode
Checking whether DHCP request messages
match entries in the DHCP snooping binding
table
Limiting the rate of sending DHCP messages
Data
Type and number of the interface that needs
to be set to be trusted
92

Advertisement

Table of Contents
loading

Table of Contents