detect spoofed giaddrs. Also, DHCP relay does not detect spoofed relay agent option
values.
Spoofed giaddrs are a concern when the DHCP relay is used if the giaddr value in
received DHCP packets is different from the local IP address on which the DHCP
relay is accessed. In this situation, DHCP relay always honors the giaddr. To configure
DHCP relay to override all giaddrs (including valid giaddrs) that are received from
downstream network elements, use the
set dhcp relay override
command with the
giaddr
keyword. DHCP relay then takes control of the client, adding its own giaddr
to the packets before forwarding the packets to the DHCP server.
Spoofed relay agent options are a concern if the giaddr is not null, or if it is null and
the DHCP relay is operating in the trust-all method. In these two situations, DHCP
relay always honors the relay agent option value in received DHCP packets.
■
To protect against spoofed giaddrs and relay agent option values:
host1(config)#
set dhcp relay override agent-option
DHCP relay then overrides all relay agent option values that are received from
downstream network elements, performing one of the following actions:
■
If the DHCP relay is configured to add relay agent option 82 to the packets,
it clears the existing option 82 values and inserts the new values.
■
If the DHCP relay is not configured to add relay agent option 82, it clears
the existing option values but does not add any new values.
Using the Broadcast Flag Setting to Control Transmission of DHCP Reply Packets
Each DHCP request packet includes a broadcast flag that, if set, specifies how to
transmit DHCP Offer reply packets and DHCP ACK and NAK reply packets to DHCP
clients during the discovery process. To configure DHCP relay and DHCP relay proxy
to use the setting of the broadcast flag to control the transmission of DHCP Offer,
DHCP ACK, and DHCP NAK reply packets, use the
set dhcp relay
broadcast-flag-replies
command from Global Configuration mode.
When you issue the
set dhcp relay broadcast-flag-replies
command, the method
that DHCP relay and DHCP relay proxy use to transmit DHCP Offer reply packets
and ACK and NAK reply packets depends on whether the broadcast flag in the DHCP
request packet is set or not set, as follows:
■
If the broadcast flag is set in the DHCP request packet, using the
set dhcp relay
broadcast-flag-replies
command causes DHCP relay and DHCP relay proxy to
broadcast DHCP reply packets to clients.
■
If the broadcast flag is not set in the DHCP request packet, using the
set dhcp
relay broadcast-flag-replies
command causes DHCP relay and DHCP relay proxy
to use the layer 2 unicast transmission method to send DHCP reply packets using
the client’s layer 2 (MAC) address and layer 3 (IP) unicast address.
There are exceptions to this behavior for DHCP relay proxy when the DHCP client
is already bound to an IP address or is renewing the lease on its IP address. For
information, see “Behavior for Bound Clients and Address Renewals” on page 514.
492
■
Configuring DHCP Relay and BOOTP Relay
JUNOSe 11.0.x Broadband Access Configuration Guide
Summary of Contents for JUNOSE 11.0.X MULTICAST ROUTING
Page 6: ...vi...
Page 28: ...xxviii Table of Contents JUNOSe 11 0 x Broadband Access Configuration Guide...
Page 36: ...xxxvi List of Tables JUNOSe 11 0 x Broadband Access Configuration Guide...
Page 42: ...2 Managing Remote Access JUNOSe 11 0 x Broadband Access Configuration Guide...
Page 204: ...164 Managing RADIUS and TACACS JUNOSe 11 0 x Broadband Access Configuration Guide...
Page 292: ...252 Monitoring RADIUS Relay Server JUNOSe 11 0 x Broadband Access Configuration Guide...
Page 336: ...296 RADIUS Client Terminate Reasons JUNOSe 11 0 x Broadband Access Configuration Guide...
Page 368: ...328 Managing L2TP JUNOSe 11 0 x Broadband Access Configuration Guide...
Page 444: ...404 PPP Accounting Statistics JUNOSe 11 0 x Broadband Access Configuration Guide...
Page 494: ...454 Managing DHCP JUNOSe 11 0 x Broadband Access Configuration Guide...
Page 510: ...470 DHCP Local Server Configuration Tasks JUNOSe 11 0 x Broadband Access Configuration Guide...
Page 556: ...516 Configuring DHCP Relay Proxy JUNOSe 11 0 x Broadband Access Configuration Guide...
Page 616: ...576 Managing the Subscriber Environment JUNOSe 11 0 x Broadband Access Configuration Guide...
Page 674: ...634 Managing Subscriber Services JUNOSe 11 0 x Broadband Access Configuration Guide...
Page 767: ...Part 7 Index Index on page 729 Index 727...
Page 768: ...728 Index JUNOSe 11 0 x Broadband Access Configuration Guide...