Validation Of Server Response Packets - HP ProCurve 2910al Switch Manual

Switches
Hide thumbs Also See for ProCurve 2910al Switch:
Table of Contents

Advertisement

IP Routing Features
Configuring DHCP Relay
Relay Agent "A"
VLAN
Client
10
DROP
Figure 3-23. Example Configured To Allow Multiple Relay Agents To Contribute an Option 82 Field
Relay Agent "A"
VLAN
Client
10
DROP
Figure 3-24. Example Allowing Only an Upstream Relay Agent To Contribute an Option 82 Field
3-56
Relay Agent "B"
VLAN
VLAN
20
20
APPEND
This is an enhancement of the previous example. In this case, each hop for an
accepted client request adds a new Option 82 field to the request. A DHCP
server capable of using multiple Option 82 fields can be configured to use this
approach to keep a more detailed control over leased IP addresses. In this
example, the primary DHCP policy boundary is at relay agent "A", but more
global policy boundaries can exist at relay agents "B" and "C".
Relay Agent "B"
VLAN
VLAN
20
20
No Option 82
Like the first example, above, this configuration drops client requests with
spurious Option 82 fields from clients on the edge relay agent. However, in
this case, only the Option 82 field from the last relay agent is retained for use
by the DHCP server. In this case the DHCP policy boundary is at relay agent
"C". In the previous two examples the boundary was with relay "A".

Validation of Server Response Packets

A valid Option 82 server response to a client request packet includes a copy
of the Option 82 field(s) the server received with the request. With validation
disabled, most variations of Option 82 information are allowed, and the
corresponding server response packets are forwarded.
Server response validation is an option you can specify when configuring
Option 82 DHCP for append, replace, or drop operation. (Refer to "Forwarding
Policies" on page 3-54.) Enabling validation on the routing switch can enhance
protection against DHCP server responses that are either from untrusted
sources or are carrying invalid Option 82 information.
Relay Agent "C"
VLAN
VLAN
30
10
APPEND
Relay Agent "C"
VLAN
VLAN
30
10
REPLACE
VLAN
DHCP
20
Option
82
Server
VLAN
DHCP
20
Option
82
Server

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents