Arp Attack Prevention; Dhcp Snooping Function - H3C LS-5100-16P-SI-OVS-H3 Configuration

Low-end ethernet switches
Table of Contents

Advertisement

H3C Low-End Ethernet Switches Configuration Examples

ARP Attack Prevention

An attacker sends numerous ARP packets to a port of a switch, which increases the
CPU load, affecting the operation of other functions and possibly causing a device to
crash.
1.2 ARP Attack Prevention
According to the characteristics of ARP attacks, H3C provides ARP attack prevention
solutions of DHCP snooping mode and authentication mode. The former solution
prevents common ARP attacks using DHCP snooping, IP static binding, ARP attack
detection, and ARP packet rate limit. The latter solution prevents gateway spoofing
attacks using IP-to-MAC binding entries provided by a CAMS server without needing to
configure attack prevention on access switches.
Table 1-1 Common network attacks and prevention methods
Gateway spoofing, spoofing gateway,
spoofing terminal users, and ARP MITM
attacks from clients that obtain IP
addresses dynamically.
Gateway spoofing, spoofing gateway,
spoofing terminal users, and ARP MITM
attacks from clients that have their IP
addresses manually configured.
ARP flood attack
Gateway spoofing attacks from clients that
have their IP addresses dynamically
obtained or manually configured.

1.2.1 DHCP Snooping Function

As a DHCP security feature, DHCP snooping can:
1)
Record IP-to-MAC bindings of DHCP clients by listening to DHCP packets.
2)
Ensure DHCP clients to obtain IP addresses from valid DHCP servers by setting
DHCP snooping trusted ports.
A trusted port forwards DHCP messages normally to guarantee that DHCP clients
can obtain valid IP addresses from a DHCP server.
An untrusted port discards the DHCP-ACK or DHCP-OFFER packets from any
DHCP server to prevent DHCP clients from receiving invalid IP addresses.
Attack
1-4
Chapter 1 ARP Attack Prevention Overview
Prevention method
DHCP snooping, ARP attack detection
IP static binding, ARP attack detection
ARP packet rate limit
ARP attack prevention solution in
authentication mode (in which a
CAMS server provides the gateway's
IP-to-MAC binding)

Advertisement

Table of Contents
loading

Table of Contents