Configuring Advanced Threat Protection
DHCP Snooping
•
Attempts to exhaust system resources so that sufficient resources are
not available to transmit legitimate traffic, indicated by an unusually
high use of specific system resources
•
Attempts to attack the switch’s CPU and introduce delay in system
response time to new network events
•
Attempts by hackers to access the switch, indicated by an excessive
number of failed logins or port authentication failures
•
Attempts to deny switch service by filling the forwarding table, indi
cated by an increased number of learned MAC addresses or a high
number of MAC address moves from one port to another
•
Attempts to exhaust available CPU resources, indicated by an
increased number of learned MAC address events being discarded
DHCP Snooping
Command
Page
dhcp-snooping
authorized-server
database
option
trust
verify
vlan
show dhcp-snooping
show dhcp-snooping stats
dhcp-snooping binding
debug dhcp-snooping
Overview
You can use DHCP snooping to help avoid the Denial of Service attacks that
result from unauthorized users adding a DHCP server to the network that then
provides invalid configuration data to other DHCP clients on the network.
10-3
Summary of Contents for PROCURVE 2910AL
Page 1: ...Access Security Guide ProCurve Switches W 14 03 2910al www procurve com ...
Page 2: ......
Page 3: ...HP ProCurve 2910al Switch February 2009 W 14 03 Access Security Guide ...
Page 84: ...Configuring Username and Password Security Front Panel Security 2 36 ...
Page 156: ...TACACS Authentication Operating Notes 4 30 ...
Page 288: ...Configuring Secure Socket Layer SSL Common Errors in SSL setup 8 22 ...
Page 416: ...Configuring Advanced Threat Protection Using the Instrumentation Monitor 10 28 ...
Page 572: ...Using Authorized IP Managers Operating Notes 14 14 ...
Page 592: ...12 Index ...
Page 593: ......