DHCP Snooping Profile
DHCP is a protocol used by DHCP servers in IP networks to dynamically allocate network configuration data to client devices (DHCP clients). Possible network configuration data includes user IP address, subnet mask, default gateway IP address, DNS server IP address, and lease duration. The DHCP protocol enables DHCP clients to be dynamically configured with such network configuration data without any manual setup process.
DHCP snooping is a security feature that helps avoid problems caused by an unauthorized DHCP server on the network that provides invalid configuration data to DHCP clients. A user without malicious intent may cause this problem by unknowingly adding to the network a switch or other device that includes a DHCP server enabled by default. In some cases, a user with malicious intent adds a DHCP server to the network as part of their Denial of Service or Man in the Middle attack.
DHCP snooping helps prevent such problems by distinguishing between trusted ports connected to legitimate DHCP servers and untrusted ports connected to general users. DHCP packets are forwarded between trusted ports without inspection. DHCP packets received on other switch ports are inspected before being forwarded. DHCP Packets from untrusted sources are dropped.
Creating a DHCP Snooping Profile
To create a DHCP Snooping profile , complete the following steps:
-
In the HPE Aruba Networking Central landing page, click the configuration
icon.
The Profiles tab is displayed. -
In the left navigation menu, select one of the following options:
-
Library—The default selection. If you create profiles in the Library, then you must assign scope and device functions to the profiles. For more information, see Assigning Scope to a DHCP Snooping Profile.
-
Global—If you create profiles at the Global level, then the profiles have Global scope assigned by default.
-
Site Collections—If you create profiles at the Site Collections level, then the profiles have site collection scope assigned by default.
-
Sites—If you create profiles at the Site level, then the profiles have site scope assigned by default.
-
Devices—If you create profiles at the Device level, then the profiles have device scope assigned by default.
-
Device Groups—If you create profiles at the Device Group level, then the profiles have device group scope assigned by default.
Note:- To create profiles at the Global level, select the device type from the Device Function drop-down list before step 4.
- To create profiles at the Site Collections, Sites, Devices, and Device Group level, complete the following steps before step 4:
- Select Site Collection, Site, Device, or Device Group in the left navigation menu.
- Select a Site Collection, Site, Device, or Device Group from the list view depending on the level where you are creating the profile.
- Select the device type from the Device Function drop-down list.
-
-
On the Network Services card, click DHCP Snooping.
Alternatively, you can complete the following steps:-
On the Network Services card, click Manage.
-
On the DHCP Snooping card, click Manage.
The DHCP Server list view is displayed.
-
-
Click Create Profile.
The Create Profile side panel is displayed.Note:You can only create a single DHCP Snooping profile within the same scope.
Gateways are compatible only with the IPv4 DHCP Snooping profile.
-
In the DHCP V4 Snooping section configure the following parameters as applicable:
-
Enable DHCP V4 Snooping—Select this checkbox to enable DHCP snooping for an IPv4 address.
-
IPv4 Verify DHCP Client Mac Address—Select this checkbox to enable the verification of DHCP client MAC addresses
-
Event Log—Select this checkbox to enable event logging.
-
Enable Option 82—Select this checkbox to enable option 82. If selected, the Remote Identifier and Action fields are displayed.
-
Remote Identifier—Select the remote identifier from the drop-down menu.
-
Action—Select the action to be performed from the drop-down menu.
-
-
External Storage—Select this checkbox to enable the use of an external storage. If selected, the following fields are displayed:
-
Select External Storage—Select the external storage from the drop-down menu.
-
Volume—Select the external storage volume from the drop-down menu.
-
Filename—Enter the file name.
-
-
-
In the Trusted IPv4 Servers section, click the add
icon.The Add Server side panel is displayed.
-
Configure the following parameters:
-
IP Address—Enter the IPv4 address.
-
VRF—Select a default or configured VRF profile from the drop-down menu.
-
-
Click Add.
-
In the DHCP V6 Snooping section, configure the following parameters as applicable:
-
Enable DHCP V6 Snooping—Select this checkbox to enable DHCP snooping for an IPv6 address.
-
Event Log—Select this checkbox to enable event logging.
-
External Storage—Select this checkbox to enable the use of an external storage. If selected, the following fields are displayed:
-
Select External Storage—Select the external storage from the drop-down menu.
-
Volume—Select the external storage volume from the drop-down menu.
-
Filename—Enter the file name.
-
-
-
In the Trusted IPv6 Servers section, click the add
icon.The Add Server side panel is displayed.
-
Configure the following parameters:
-
IP Address—Enter the IPv6 address.
-
VRF—Select a default or configured VRF profile from the drop-down menu.
-
-
Click Add.
-
Click Create.
Assigning Scope to a DHCP Snooping Profile
You must assign a scope and device function to a DHCP Snooping profile created in the Library.
To assign scope to a profile, complete the following steps:
-
In the HPE Aruba Networking Central landing page, click the configuration
icon.
The Profiles tab is displayed. -
Ensure that the default option Library is selected in the left navigation menu.
-
On the Network Services card, click DHCP Server.
Alternatively, you can complete the following steps:-
On the Network Services card, click Manage.
-
On the DHCP Relay card, click Manage.
The DHCP Relay list view is displayed.
-
-
Hover on the profile to which you want to assign a scope and click the ellipsis
icon. -
Select Assign.
The Assign Profile side panel is displayed.
-
Select the device types from Device Function list.
-
To add a scope, click the Add
icon on the Scopes table. -
Select a scope from the following Scope Level options in the drop-down list.
-
Global—Selecting this option assigns the scope at the Global level.
-
Site Collections—Select the site collections from the Assign to Scope drop-down list.
-
Sites—Select the sites from the Assign to Scope drop-down list.
-
Devices—Select the devices from the Assign to Scope drop-down list.
-
Device Groups—Select the device groups from the Assign to Scope drop-down list.
-
-
Click Add.
The Scopes table displays the newly added scopes.
-
Click Assign.
The DHCP Relay list displays the device functions and number of scopes assigned to the profile.
-
To unassign a scope from a profile, complete the following steps:
-
Hover on the profile name and click the ellipsis
icon. -
Select Unassign.
-
Select the required scope and click Unassign.
-
-
To customize the DHCP Snooping profile list, click the Customize Columns
icon.