Snooping Database Alteration Attacks - Juniper JUNOS OS 10.3 - SOFTWARE Manual

For ex series ethernet switches
Hide thumbs Also See for JUNOS OS 10.3 - SOFTWARE:
Table of Contents

Advertisement

Complete Software Guide for Junos
Meaning
Related
Documentation
Example: Configuring Allowed MAC Addresses to Protect the Switch from DHCP

Snooping Database Alteration Attacks

Requirements
2870
®
OS for EX Series Ethernet Switches, Release 10.3
ge-0/0/1.0
ge-0/0/2.0
ge-0/0/3.0
The sample output shows the number of ARP packets received and inspected per
interface, with a listing of how many packets passed and how many failed the inspection
on each interface. The switch compares the ARP requests and replies against the entries
in the DHCP snooping database. If a MAC address or IP address in the ARP packet does
not match a valid entry in the database, the packet is dropped.
Example: Configuring Port Security, with DHCP Snooping, DAI, MAC Limiting, and MAC
Move Limiting, on an EX Series Switch on page 2849
Enabling DHCP Snooping (CLI Procedure) on page 2910
Enabling DHCP Snooping (J-Web Procedure) on page 2911
Enabling Dynamic ARP Inspection (CLI Procedure) on page 2913
Enabling Dynamic ARP Inspection (J-Web Procedure) on page 2914
In one type of attack on the DHCP snooping database, an intruder introduces a DHCP
client on an untrusted access interface with a MAC address identical to that of a client
on another untrusted interface. The intruder then acquires the DHCP lease of that other
client, thus changing the entries in the DHCP snooping table. Subsequently, what would
have been valid ARP requests from the legitimate client are blocked.
This example describes how to configure allowed MAC addresses, a port security feature,
to protect the switch from DHCP snooping database alteration attacks:
Requirements on page 2870
Overview and Topology on page 2871
Configuration on page 2872
Verification on page 2872
This example uses the following hardware and software components:
One EX Series switch
Junos OS Release 9.0 or later for EX Series switches
A DHCP server to provide IP addresses to network devices on the switch
Before you configure specific port security features to mitigate common access-inteface
attacks, be sure you have:
Connected the DHCP server to the switch.
7
5
10
10
12
12
Copyright © 2010, Juniper Networks, Inc.
2
0
0

Advertisement

Table of Contents
loading

Table of Contents