Snooping Database Alteration Attacks - Juniper JUNOS OS 10.4 - FOR EX REV 1 Manual

For ex series ethernet switches
Table of Contents

Advertisement

Complete Software Guide for Junos
Meaning
Related
Documentation
Example: Configuring Allowed MAC Addresses to Protect the Switch from DHCP

Snooping Database Alteration Attacks

Requirements
3094
®
OS for EX Series Ethernet Switches, Release 10.4
ge-0/0/1.0
ge-0/0/2.0
ge-0/0/3.0
The sample output shows the number of ARP packets received and inspected per
interface, with a listing of how many packets passed and how many failed the inspection
on each interface. The switch compares the ARP requests and replies against the entries
in the DHCP snooping database. If a MAC address or IP address in the ARP packet does
not match a valid entry in the database, the packet is dropped.
Example: Configuring Port Security, with DHCP Snooping, DAI, MAC Limiting, and MAC
Move Limiting, on an EX Series Switch on page 3073
Enabling DHCP Snooping (CLI Procedure) on page 3134
Enabling DHCP Snooping (J-Web Procedure) on page 3135
Enabling Dynamic ARP Inspection (CLI Procedure) on page 3137
Enabling Dynamic ARP Inspection (J-Web Procedure) on page 3138
In one type of attack on the DHCP snooping database, an intruder introduces a DHCP
client on an untrusted access interface with a MAC address identical to that of a client
on another untrusted interface. The intruder then acquires the DHCP lease of that other
client, thus changing the entries in the DHCP snooping table. Subsequently, what would
have been valid ARP requests from the legitimate client are blocked.
This example describes how to configure allowed MAC addresses, a port security feature,
to protect the switch from DHCP snooping database alteration attacks:
Requirements on page 3094
Overview and Topology on page 3095
Configuration on page 3096
Verification on page 3096
This example uses the following hardware and software components:
One EX Series switch
Junos OS Release 9.0 or later for EX Series switches
A DHCP server to provide IP addresses to network devices on the switch
Before you configure specific port security features to mitigate common access-inteface
attacks, be sure you have:
Connected the DHCP server to the switch.
7
5
10
10
12
12
Copyright © 2010, Juniper Networks, Inc.
2
0
0

Advertisement

Table of Contents
loading

This manual is also suitable for:

Junos os 10.4

Table of Contents