Dhcp Mac Source Address Validation - Dell Force10 Z9000 Configuration Manual

Ftos configuration guide for z9000 system
Hide thumbs Also See for Force10 Z9000:
Table of Contents

Advertisement

The DHCP binding table associates addresses assigned by the DHCP servers, with the port on which the
requesting client is attached. When IP Source Address Validation is enabled on a port, the system verifies
that the source IP address is one that is associated with the incoming port. If an attacker is impostering as a
legitimate client the source address appears on the wrong ingress port, and the system drops the packet.
Likewise, if the IP address is fake, the address will not be on the list of permissible addresses for the port,
and the packet is dropped.
Task
Enable IP Source Address Validation

DHCP MAC Source Address Validation

DHCP MAC Source Address Validation (SAV) validates a DHCP packet's source hardware address
against the client hardware address field (CHADDR) in the payload.
FTOS Release 8.2.1.1 ensures that the packet's source MAC address is checked against the CHADDR
field in the DHCP header only for packets from snooped VLANs.
Task
Enable DHCP MAC Source Address
Validation.
IP+MAC Source Address Validation
IP+MAC Source Address Validation
IP Source Address Validation validates the IP source address of an incoming packet against the DHCP
Snooping binding table. IP+MAC Source Address Validation ensures that the IP source address and MAC
source address are a legitimate pair, rather validating each attribute individually. IP+MAC Source Address
Validation cannot be configured with IP Source Address Validation.
Step
Task
1
Allocate at least one FP block to the
ipmacacl CAM region.
2
Save the running-config to the
startup-config.
3
Reload the system.
4
Enable IP+MAC Source Address
Validation.
|
Dynamic Host Configuration Protocol (DHCP)
330
Command Syntax
ip dhcp
source-address-validation
Command Syntax
ip dhcp snooping verify
mac-address
is available on platforms:
Command Syntax
cam-acl l2acl
copy running-config startup-config
reload
ip dhcp source-address-validation
ipmac
Command Mode
INTERFACE
Command Mode
CONFIGURATION
c s z
Command Mode
CONFIGURATION
EXEC Privilege
EXEC Privilege
INTERFACE

Advertisement

Table of Contents
loading

Table of Contents