IP Routing Features
Configuring DHCP Relay
Server response validation is an option you can specify when configuring
Option 82 DHCP for
append
,
replace
, or
drop
operation. (Refer to “Forwarding
Policies” on page 7-34.) Enabling validation on the routing switch can enhance
protection against DHCP server responses that are either from untrusted
sources or are carrying invalid Option 82 information.
With validation enabled, the relay agent applies stricter rules to variations in
the Option 82 field(s) of incoming server responses to determine whether to
forward the response to a downstream device or to drop the response due to
invalid (or missing) Option 82 information. Table <zBlue>7-4, below, illus
trates relay agent management of DHCP server responses with optional
validation enabled and disabled.
Table 7-4.
Relay Agent Management of DHCP Server Response Packets
Response Packet Content
Option 82
Configuration
Validation Enabled on the Relay
Agent
Validation Disabled (The
Default)
Valid DHCP server response
packet without an Option 82
field.
append
,
replace
,
or
drop
1
Drop the server response
packet.
Forward server response
packet to a downstream device.
keep
2
Forward server response
packet to a downstream device.
Forward server response
packet to a downstream device.
The server response packet
carries data indicating a given
routing switch is the primary relay
agent for the original client
request, but the associated
Option 82 field in the response
contains a
Remote ID
and
Circuit
ID
combination that did not origi
nate with the given relay agent.
append
Drop the server response
packet.
Forward server response
packet to a downstream device.
replace
or
drop
1
Drop the server response
packet.
Drop the server response
packet.
keep
2
Forward server response
packet to a downstream device.
Forward server response
packet to a downstream device.
The server response packet
carries data indicating a given
routing switch is the primary relay
agent for the original client
request, but the associated
Option 82 field in the response
contains a
Remote ID
that did not
originate with the relay agent.
append
Drop the server response
packet.
Forward server response
packet to a downstream device.
replace
or
drop
1
Drop the server response
packet.
Drop the server response
packet.
keep
2
Forward server response
packet to a downstream device.
Forward server response
packet to a downstream device.
All other server response
packets
3
append
,
keep
2
,
replace
, or
drop
1
Forward server response
packet to a downstream device.
Forward server response
packet to a downstream device.
1
Drop is the recommended choice because it protects against an unauthorized client inserting its own Option 82 field for
an incoming request.
2
A routing switch with DHCP Option 82 enabled with the
keep
option forwards all DHCP server response packets except
those that are not valid for either Option 82 DHCP operation (compliant with RFC 3046) or DHCP operation without Option
82 support (compliant with RFC 2131).
3
A routing switch with DHCP Option 82 enabled drops an inbound server response packet if the packet does not have
any device identified as the primary relay agent (
giaddr
= null; refer to RFC 2131).
7-37
Содержание 2610
Страница 1: ...Advanced Traffic Management Guide 2610 2610 PWR ProCurve Switches R 11 XX www procurve com ...
Страница 2: ......
Страница 3: ...ProCurve Switch 2610 Series Switch 2610 PWR Series December 2007 Advanced Traffic Management Guide ...
Страница 14: ...xii ...
Страница 20: ...Product Documentation xviii ...
Страница 84: ...GVRP Introduction 3 18 ...
Страница 108: ...Multimedia Traffic Control with IP Multicast IGMP Excluding Multicast Addresses from IP Multicast Filtering 4 24 ...
Страница 190: ...Spanning Tree Operation 802 1s Multiple Spanning Tree Protocol MSTP 5 82 ...
Страница 258: ...Quality of Service QoS Managing Bandwidth More Effectively QoS Operating Notes and Restrictions 6 68 ...
Страница 306: ...IP Routing Features UDP Broadcast Forwarding 7 48 ...
Страница 354: ...ProCurve Stack Management Configuring Stack Management 8 48 ...
Страница 363: ......
Страница 364: ... Copyright 2007 Hewlett Packard Development Company L P December 2007 Manual Part Number 5991 8641 ...