SNR S2989G-24TX-UPS — dHCPv6 Configuration Guide: Options 37 and 38 Explained [522/553]

Превью страниц Страница 522 / 553
SNR S2989G-24TX-POE [522/553] Dhcpv6 option37 38 configuration task list
S2989G-24TX Operation Manual
Chapter 11 IPv6 Configuration
11-12
There are some problems when using DHCPv6 relay agent, for example: How to
assign IP address in the fixed range to the specifiec users? How to avoid illegal DHCPv6
client to forge IP address exhaust attack triggered by MAC address fields of DHCPv6
packets? How to avoid illegal DHCPv6 client to trigger deny service attack through using
MAC address of other legal clients? Therefore, IETF set rfc4649 and rfc4580, i.e.
DHCPv6 option 37 and option 38 to solve these problems.
DHCPv6 option 37 and option 38 is similar to DHCP option 82. When DHCPv6 client
sends request packets to DHCPv6 server though DHCPv6 relay agent, if DHCPv6 relay
agent supports option 37 and option 38, they will be added to request packets. For the
respond packets of server, option 37 and option 38 are meaningless and are peeled from
the respond packets. Therefore, the application of option 37 and option 38 is transparent
for client.
DHCPv6 server can authenticate identity of DHCPv6 client and DHCPv6 relay device
by option 37 and option 38, assign and manage client address neatly through configuring
the assign policy, prevent DHCPv6 attack availably according to the inclusive client
information, such as forging MAC address fields of DHCPv6 packets to trigger IP address
exhaust attack. Since server can identify multiple request packets from the same access
port, it can assign the address number through policy limit to avoid address exhaust.
However, rfc4649 and rfc4580 do not set how to use opton 37 and option 38 for DHCPv6
server, users can use it neatly according to their own demand.
11.2.2
DHCPv6 option37, 38 Configuration Task List
1. Dhcpv6 snooping option basic functions configuration
2. Dhcpv6 relay option basic functions configuration
3. Dhcpv6 server option basic functions configuration
1. DHCPv6 snooping option basic functions configuration
Command
Description
Global mode
ipv6 dhcp snooping remote-id option
no ipv6 dhcp snooping remote-id option
This command enables
DHCPv6 SNOOPING to
support option 37 option, no
command disables it.
ipv6 dhcp snooping subscriber-id option
no ipv6 dhcp snooping subscriber-id option
This command enables
DHCPv6 SNOOPING to
support option 38 option, no
command disables it.

Содержание

666

Узнайте, как настроить DHCPv6 с использованием опций 37 и 38 для предотвращения атак и управления адресами. Полное руководство по конфигурации и функциям.