Juniper JUNOS OS 10.4 - FOR EX REV 1 Manual page 3191

For ex series ethernet switches
Table of Contents

Advertisement

Example: Configuring MAC Limiting to Protect the Switch from DHCP Starvation
Attacks
Requirements
Overview and Topology
Copyright © 2010, Juniper Networks, Inc.
In a DHCP starvation attack, an attacker floods an Ethernet LAN with DHCP requests
from spoofed (counterfeit) MAC addresses. The switch's trusted DHCP server or servers
cannot keep up with the requests and can no longer assign IP addresses and lease times
to legitimate DHCP clients on the switch. Requests from those clients are either dropped
or directed to a rogue DHCP server set up by the attacker.
This example describes how to configure MAC limiting, a port security feature, to protect
the switch against DHCP starvation attacks:
Requirements on page 3087
Overview and Topology on page 3087
Configuration on page 3088
Verification on page 3089
This example uses the following hardware and software components:
One EX Series switch
Junos OS Release 9.0 or later for EX Series switches
A DHCP server to provide IP addresses to network devices on the switch
Before you configure MAC limiting, a port security feature, to mitigate DHCP starvation
attacks, be sure you have:
Connected the DHCP server to the switch.
Configured the VLAN
employee-vlan
with Multiple VLANs for EX Series Switches" on page 1532.
Ethernet LANs are vulnerable to address spoofing and DoS attacks on network devices.
This example describes how to protect the switch against one common type of attack,
a DHCP starvation attack.
This example shows how to configure port security features on an EX3200-24P switch
that is connected to a DHCP server.
The setup for this example includes the VLAN
for creating that VLAN is described in the topic "Example: Setting Up Bridging with Multiple
VLANs for EX Series Switches" on page 1532. That procedure is not repeated here. Figure
78 on page 3088 illustrates the topology for this example.
Chapter 100: Examples: Port Security Configuration
on the switch. See "Example: Setting Up Bridging
employee-vlan
on the switch. The procedure
3087

Advertisement

Table of Contents
loading

This manual is also suitable for:

Junos os 10.4

Table of Contents