Chapter 19 Dhcp Snooping Configuration; Dhcp Snooping Introduction; Dhcp Snooping Configuration; Dhcp Snooping Configuration Task List - Digitalchina Networks DCS-3950 series Manual

Table of Contents

Advertisement

Chapter 19 DHCP Snooping

19.1 DHCP Snooping Introduction

DHCP Snooping can effectively block attacks from fake DHCP servers.
Defense against Fake DHCP Server:once the switch intercepts the DHCP server reply
packets from un-trusted ports(including DHCPOFFER, DHCPACK, and DHCPNAK), it
will alarm the users and respond according to the situation(shutdown the port or send
BlackHole) 。
Defense against DHCP over load attacks:To avoid too many DHCP messages
attacking CPU, users should limit the speed of DHCP to receive packets on trusted and
un-trusted ports.
Record the binding data of DHCP:DHCP SNOOPING will record the binding data of
DHCP SERVER while forwarding DHCP messages, it can also upload the binding data to
the specified server to backup it. The binding data is mainly used to configure the
dynamic users of dot1x userbased ports. Please refer to the chapter named 'dot1x
configuration' to find more about the usage of dot1x userbased mode.
Add binding ARP: DHCP SNOOPING can add static binding ARP according to the
binding data after capturing binding data, thus to avoid ARP cheating.
Add trusted users:DHCP SNOOPING can add trusted user list entries according to the
parameters in binding data after capturing binding data; thus these users can access all
resources without DOT1X authentication.
Automatic Recovery:A while after the switch shut down the port or sent blockhole, it
should automatically recover the communication of the port or source MAC and send
information to Log Server via syslog
LOGF Function:When the switch discovers abnormal received packets or automatically
recovers, it should send syslog information to Log Server

19.2 DHCP Snooping Configuration

19.2.1 DHCP Snooping Configuration Task List

1. Enable DHCP Snooping
2. Enable the binding function of DHCP Snooping
3. Enable ARP binding for DHCP snooping.
4. Configure helper server address
5. Configure trusted ports
DCS-3950 series Ethernet switch manual
Configuration
318

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents