Dhcp Mac Source Address Validation - Dell Force10 S4810P Configuration Manual

High-density, 1ru 48-port 10gbe switch
Hide thumbs Also See for Force10 S4810P:
Table of Contents

Advertisement

The DHCP binding table associates addresses assigned by the DHCP servers, with the port on which the
requesting client is attached. When IP Source Address Validation is enabled on a port, the system verifies
that the source IP address is one that is associated with the incoming port. If an attacker is impostering as a
legitimate client the source address appears on the wrong ingress port, and the system drops the packet.
Likewise, if the IP address is fake, the address will not be on the list of permissible addresses for the port,
and the packet is dropped.
Task
Enable IP Source Address Validation
Note: If IP Source Guard is enabled using the
187 entries or more in the current DHCP snooping binding table, Source Address Validation (SAV) may
not be applied to all entries.
To ensure that SAV is applied correctly to all entries, enable the
command before adding entries to the binding table.

DHCP MAC Source Address Validation

DHCP MAC Source Address Validation (SAV) validates a DHCP packet's source hardware address
against the client hardware address field (CHADDR) in the payload.
FTOS Release 8.2.1.1 ensures that the packet's source MAC address is checked against the CHADDR
field in the DHCP header only for packets from snooped VLANs.
Task
Enable DHCP MAC Source Address Validation.
IP+MAC Source Address Validation
The following feature is available on platforms:
IP Source Address Validation validates the IP source address of an incoming packet against the DHCP
Snooping binding table. IP+MAC Source Address Validation ensures that the IP source address and MAC
source address are a legitimate pair, rather validating each attribute individually. IP+MAC Source Address
Validation cannot be configured with IP Source Address Validation.
Step
Task
1
Allocate at least one FP block to the
ipmacacl CAM region.
2
Save the running-config to the
startup-config.
3
Reload the system.
394
|
Dynamic Host Configuration Protocol (DHCP)
Command Syntax
ip dhcp source-address-validation
ip dhcp source-address-validation
Command Syntax
ip dhcp snooping verify mac-address
c
s
,
Command Syntax
cam-acl l2acl
copy running-config startup-config
reload
Command Mode
INTERFACE
command and there are
ip dhcp source-address-validation
and
.
Command Mode
CONFIGURATION
Command Mode
CONFIGURATION
EXEC Privilege
EXEC Privilege

Advertisement

Table of Contents
loading

Table of Contents