Juniper JUNOS OS 10.4 - FOR EX REV 1 Manual page 54

For ex series ethernet switches
Table of Contents

Advertisement

Complete Software Guide for Junos
Chapter 100
Chapter 101
liv
®
OS for EX Series Ethernet Switches, Release 10.4
DHCP Option 82 Processing . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3064
Suboption Components of Option 82 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3065
Configurations of the EX Series Switch That Support Option 82 . . . . . . . 3066
Switch and Clients Are on Same VLAN as DHCP Server . . . . . . . . . . . 3066
Switch Acts as Relay Agent . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3066
IP Address Spoofing . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3068
How IP Source Guard Works . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3068
The IP Source Guard Database . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3068
Typical Uses of Other Junos Operating System (Junos OS) Features with
IP Source Guard . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3069
Understanding Proxy ARP on EX Series Switches . . . . . . . . . . . . . . . . . . . . . . . 3070
Proxy ARP Overview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3070
Best Practices for Proxy ARP on EX Series Switches . . . . . . . . . . . . . . . . . . 3071
Examples: Port Security Configuration . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3073
Example: Configuring Port Security, with DHCP Snooping, DAI, MAC Limiting,
and MAC Move Limiting, on an EX Series Switch . . . . . . . . . . . . . . . . . . . . 3073
Addresses, to Protect the Switch from Ethernet Switching Table Overflow
Attacks . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3080
Example: Configuring a DHCP Server Interface as Untrusted to Protect the Switch
from Rogue DHCP Server Attacks . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3083
Example: Configuring MAC Limiting to Protect the Switch from DHCP Starvation
Attacks . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3087
Example: Configuring DHCP Snooping and DAI to Protect the Switch from ARP
Spoofing Attacks . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3090
Example: Configuring Allowed MAC Addresses to Protect the Switch from DHCP
Snooping Database Alteration Attacks . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3094
Example: Configuring DHCP Snooping, DAI , and MAC Limiting on an EX Series
Example: Configuring IP Source Guard with Other EX Series Switch Features to
Mitigate Address-Spoofing Attacks on Untrusted Access Interfaces . . . . . 3104
Example: Configuring IP Source Guard on a Data VLAN That Shares an Interface
with a Voice VLAN . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3112
Between Clients and a DHCP Server . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3119
Example: Setting Up DHCP Option 82 on an EX Series Switch with No Relay
Agent Between Clients and DHCP Server . . . . . . . . . . . . . . . . . . . . . . . . . . . 3122
Example: Configuring Proxy ARP on an EX Series Switch . . . . . . . . . . . . . . . . . . 3125
Configuring Port Security . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3129
Configuring Port Security (CLI Procedure) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3130
Configuring Port Security (J-Web Procedure) . . . . . . . . . . . . . . . . . . . . . . . . . . . 3131
Enabling DHCP Snooping (CLI Procedure) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3134
Enabling DHCP Snooping (J-Web Procedure) . . . . . . . . . . . . . . . . . . . . . . . . . . . 3135
Enabling a Trusted DHCP Server (CLI Procedure) . . . . . . . . . . . . . . . . . . . . . . . . 3136
Enabling a Trusted DHCP Server (J-Web Procedure) . . . . . . . . . . . . . . . . . . . . . 3136
Copyright © 2010, Juniper Networks, Inc.

Advertisement

Table of Contents
loading

This manual is also suitable for:

Junos os 10.4

Table of Contents