Inspecting and tracking dhcp packets, Tracking of dhcp assignments, Dynamic arp inspection – Brocade BigIron RX Series Configuration Guide User Manual

Page 1161: Chapter 36, Inspecting and, Tracking dhcp packets, Dynamic arp, Inspection

Advertising
background image

BigIron RX Series Configuration Guide

1083

53-1002484-04

Chapter

36

Inspecting and Tracking DHCP Packets

In this chapter

Tracking of DHCP assignments. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1083

Dynamic ARP inspection . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1083

DHCP snooping . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1088

DHCP relay agent information (DHCP option 82) . . . . . . . . . . . . . . . . . . 1090

IP source guard . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1093

Tracking of DHCP assignments

For enhanced network security, you can configure the Brocade device to inspect and keep track of
Dynamic Host Configuration Protocol (DHCP) assignments. To do so, use the following features.

Dynamic ARP inspection

NOTE

This feature is only supported on Layer 3 code.

Dynamic ARP Inspection (DAI) enables the Brocade device to intercept and examine all ARP request
and response packets in a subnet and discard those packets with invalid IP to MAC address
bindings. DAI can prevent common man-in-the-middle (MiM) attacks such as ARP cache poisoning,
and disallow mis-configuration of client IP addresses.

TABLE 178

Chapter contents

Description

See page

Dynamic ARP Inspection – Intercepts and examines all ARP request and response
packets in a subnet, and blocks all packets that have invalid IP to MAC address bindings

page 1083

DHCP Snooping – Filters replay DHCP packets from untrusted ports (those connected to
host ports), and allows DHCP packets from trusted ports (those connected to DHCP
servers)

page 1088

IP Source Guard – Permits traffic with valid source IP addresses only, which is learned
from Dynamic ARP Inspection or DHCP snooping

page 1093

Advertising