Complete Software Guide for Junos
Chapter 100
Chapter 101
liv
®
OS for EX Series Ethernet Switches, Release 10.4
Suboption Components of Option 82 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3065
Configurations of the EX Series Switch That Support Option 82 . . . . . . . 3066
Switch and Clients Are on Same VLAN as DHCP Server . . . . . . . . . . . 3066
Switch Acts as Relay Agent . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3066
IP Address Spoofing . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3068
Typical Uses of Other Junos Operating System (Junos OS) Features with
IP Source Guard . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3069
Proxy ARP Overview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3070
Examples: Port Security Configuration . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3073
Example: Configuring Port Security, with DHCP Snooping, DAI, MAC Limiting,
Addresses, to Protect the Switch from Ethernet Switching Table Overflow
Attacks . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3080
Example: Configuring a DHCP Server Interface as Untrusted to Protect the Switch
Example: Configuring MAC Limiting to Protect the Switch from DHCP Starvation
Attacks . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3087
Example: Configuring DHCP Snooping and DAI to Protect the Switch from ARP
Spoofing Attacks . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3090
Example: Configuring Allowed MAC Addresses to Protect the Switch from DHCP
Example: Configuring DHCP Snooping, DAI , and MAC Limiting on an EX Series
Example: Configuring IP Source Guard with Other EX Series Switch Features to
Mitigate Address-Spoofing Attacks on Untrusted Access Interfaces . . . . . 3104
Example: Configuring IP Source Guard on a Data VLAN That Shares an Interface
with a Voice VLAN . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3112
Between Clients and a DHCP Server . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3119
Example: Setting Up DHCP Option 82 on an EX Series Switch with No Relay
Agent Between Clients and DHCP Server . . . . . . . . . . . . . . . . . . . . . . . . . . . 3122
Configuring Port Security . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3129
Copyright © 2010, Juniper Networks, Inc.