Correct configuration of dhcp-snooping on OS6560

Post Reply
Reginaldo
Member
Posts: 5
Joined: 23 Nov 2023 12:50

Correct configuration of dhcp-snooping on OS6560

Post by Reginaldo »

Hello!

I have some doubts regarding the correct configuration of dhcp-snooping on the Alcatel model: OS6560.

I have used the configuration below:

dhcp-snooping admin-state enable
dhcp-snooping binding admin-state enable
dhcp-snooping port 1/1/47-48 trust

Doubts:
- Does this configuration of mine really block, for example, the use of strange DHCP on my network?
- On Cisco equipment, it is necessary to configure the number of each vlan in dhcp-snooping, in the case of Alcatel it is also necessary, how to do it?
- Does the dhcp-snooping configuration consume a lot of switch CPU usage?
- To configure dhcpv6 on this model, do I use exactly these same commands or are there variations?

If there is any suggestion for better use of dhcp-snooping, I would appreciate your collaboration.

Best regards!
silvio
Alcatel Unleashed Certified Guru
Alcatel Unleashed Certified Guru
Posts: 1894
Joined: 01 Jul 2008 10:51
Location: Germany

Re: Correct configuration of dhcp-snooping on OS6560

Post by silvio »

To forbid unwanted dhcp server (for all vlans) the first und the last line are enough. You can reach the same result with the feature UserPorts.
With dhcp-snooping you have on top the possibility to protect against arp-spoofing attacks. For this you need the binding and the ip-source-filter.
regards
Silvio
Reginaldo
Member
Posts: 5
Joined: 23 Nov 2023 12:50

Re: Correct configuration of dhcp-snooping on OS6560

Post by Reginaldo »

Thanks for the instructions, Silvio!

Just confirming what the best protection for my network looks like.
Both for strange dhcp and arp-spoofing attack protection.
Would the settings be like this?

dhcp-snooping admin-state enable
dhcp-snooping binding admin-state enable
dhcp-snooping ip-source-filter port 1/1/1-46 admin-state enable
dhcp-snooping port 1/1/47-48 trust


One last question. Should ip-source-filter be configured on all ports or only untrusted ones?


Thanks!
silvio
Alcatel Unleashed Certified Guru
Alcatel Unleashed Certified Guru
Posts: 1894
Joined: 01 Jul 2008 10:51
Location: Germany

Re: Correct configuration of dhcp-snooping on OS6560

Post by silvio »

normaly you configure dhcp-snooping at the access switch. So the trust ports are the uplink to core.
ISF is for the user ports - so the untrust port. Your config is correct. But you need to know: If you activate ISF than only the clients within the binding table are able to communicate. If you activate all the commands during the working hours than the clients need to restart (or to get a new ip address).
BR Silvio
User avatar
Cristek
Member
Posts: 7
Joined: 08 Mar 2024 10:56

Re: Correct configuration of dhcp-snooping on OS6560

Post by Cristek »

Hi,
Not OP but mind if I throw a question in? ISF, where would you typically use this?
I mean, if you use it on a port that has an AP connected to it, then when the user roams to another AP won't they be blocked then, correct?
What's the typical use for this feature?
User avatar
Gleylancer
Member
Posts: 156
Joined: 08 May 2013 03:14

Re: Correct configuration of dhcp-snooping on OS6560

Post by Gleylancer »

DHCP snooping is to find DHCP -Servers- and instantly block them, not DHCP clients. Wireless Roaming has nothing to do with this.
silvio
Alcatel Unleashed Certified Guru
Alcatel Unleashed Certified Guru
Posts: 1894
Joined: 01 Jul 2008 10:51
Location: Germany

Re: Correct configuration of dhcp-snooping on OS6560

Post by silvio »

ISF protects against arp spoofing attacks. If a wireless client is rooming between APs at the same switch there should be no impact. But if the client is rooming to an AP at another switch than the entry in the binding table don't know the client - and it will be blocked.
So at ports to APs I would ISF not activate.
BR Silvio
User avatar
Cristek
Member
Posts: 7
Joined: 08 Mar 2024 10:56

Re: Correct configuration of dhcp-snooping on OS6560

Post by Cristek »

Gleylancer wrote: 25 Mar 2024 11:40 DHCP snooping is to find DHCP -Servers- and instantly block them, not DHCP clients. Wireless Roaming has nothing to do with this.
Hi,
I was referring to ISF and not DHCP-snooping. Silvio already replied and cleared by doubt. It's a bad idea as I was wondering myself!
BR :)
Post Reply

Return to “OmniSwitch 6560”