function of guard of source IP and dhcp DHCP scope of exhaustion (customer parodies other customers)

Hello world.

A dhcp server assigns ip address based on the mac address by equipment of the customer field in the dhcp packets.

A potential attack is when a crowd of thugs mimics different mac addresses and causes the dhcp server to assign ip addresses until no ip address is left for legitimate host.

For example, a host with mac1 h1 is designated by the ip address of the dhcp server as:

199.199.199.1 mac1

DHCP server has this entry in its database.

Using hacking tools such as Yersinia or Gobbler can create a DHCP discover messages every time that create another mac for material scope of the client to the dhcp server, thereby causing a dhcp server to assign ip addresses because they are of legitimate dhcp to dhcp server discover messages with matching each another Mac in hardware of client addresses.

You could use dhcp snooping and it will avoid that (exhaustion of dhcp scope) and configure the switch to check if the CBC mac fits the hardware address of the client in the dhcp message. But when even we can creat spoofed discover messages where mac src in the ethernet header will match the client hardware address in dhcp discovery message. It did not always overcome the problem.

You might say use IP source guard characteristic but it really will prevent this problem from happening?

Let me illustrate:

H1 - f1/1SW - DHCP server

Let's say that we have configured dhcp snooping on sw1 and f1/1 is untrusted port.  Switch a suite dhcp binding

199.199.199.1 mac1 vlan1 f1/1

Then, we configure source ip guard in order to validate the mac src and src ip against the dhcp bindings. When you configure keep source ip first, it will allow dhcp only if a host can request ip address and dhcp binding can be built. After that IP keep source will validate ip or mac src src or both against the binding.depending dhcp on how configure us source ip guard.

In our case, we have configured source ip guard in order to validate the mac src and src ip against the dhcp binding.

A dhcp connection is already created as:

199.199.199.1 mac1 vlan 1 f1/1

Now, using hacking tools Yersinia or Gobbler on h1, we create our first spoofed dhcp discovery message where mac src = mac2 ethernet header and client harware address = mac2 in dhcp discovery message. As the switch is configured with the function of guard of source ip and therefore allows dhcp discover message to pass through. DHCP server after you receive the message dhcp assigns another IP from the pool. The dhcp server has now after the entries:

199.199.199.1 mac1

199.199.199.2 mac2.

We continue to spoofed dhcp to craft discover messages as described above and are dhcp server keep ip address assignment until exhausts the entire pool.

So my question is how ip source guard in conjunction with dhcp snooping doesn't stop this attack does not happen? (IE DHCP scope exhaustion)

I really appreciate your comments.

Thank you and have a week.

Hi Sara,.

Ask was quite interesting. As far as I know that whatever it is port snooping untrusted won't let your fake dhcp server.

You can take this query in the Sub forum of experts mentioned that is specific for dhcp snooping and source of guard.

https://supportforums.Cisco.com/message/3689811#3689811

Please assess whether the information provided is useful.

By

Knockaert

Tags: Cisco Security

Similar Questions

  • Functional Global run from Source executable vs

    Hello...  Imagine a Global functional simple (shift registers loop not initialized on some time with the internal Structure of a case Set/Get) where, in a case I run the source code and I use the setting mode to enter data in the flowing shift to the relatively high rate register, say once per second.  Then I, running on the same computer, an another bifurcation of the overall even where to get data at a slower pace, I say once per minute...  And in fact, what I'm doing here is to have three different instances, data from Global setting on three different materials and then I use a case set to Get to get all three samples of data at a lower rate (I try only to see the data to change on a second period 60...)  When I'm building it from source code and run it, everything works perfectly...  I put the data of three different instances of the total from three different sources...  Then I translate all together in one place and use a Global example, set to Get to get all three items of data once per minute more...  So far so good..

    But in my real-world deployment, I can't run Source code.  I need compile this code in executable files...  I got it done and tested...  The three different Set executables seem to work very well, but the Get instance in executable form has no data.  I built this test because I realized that I'm not sure how this Global Set/Get functional concept works at the level of the compiled code...  Am I missing something?  It is possible to work somehow?

    What should I do to get the data to be read in the Global functional (Get) when I work at the level of the executable?  Any help on this would be much appreciated... Thanks bob...

    Why do you need 4 executables?

    You could launch each vi dynamically from the main vi, and then they run independent, but still be able to use the FG.

  • whenever I start my PC security guard windows popping up and tells me runll32.exe is corrupt

    original title: help with rundll32.exe

    whenever I start my PC security guard windows popping up and tells me runll32.exe is corrupt and has won, t let me not do anything just guard telling me that I've been infiltrated with a virus and I try to open all of the files are corrupted. What can I do to stop this?

    Hello

    If you need search malware here's my recommendations - they will allow you to
    scrutiny and the withdrawal without ending up with a load of spyware programs running
    resident who can cause as many questions as the malware and may be more difficult to detect as the
    cause.

    No one program cannot be used to detect and remove any malware. Added that often easy
    to detect malicious software often comes with a much harder to detect and remove the payload. Then
    its best to be thorough than paying the high price later now too. Check with them to one
    extreme overkill point and then run the cleaning only when you are sure that the system is clean.

    It can be made repeatedly in Mode safe - F8 tap that you start, however, you must also run
    the regular windows when you can.

    TDSSKiller.exe. - Download the desktop - so go ahead and right-click on it - RUN AS ADMIN
    It will display all the infections in the report after you run - if it will not run changed the name of
    TDSSKiller.exe to tdsskiller.com. If she finds something or not does not mean that you should not
    check with the other methods below.
    http://support.Kaspersky.com/viruses/solutions?QID=208280684

    Download malwarebytes and scan with it, run MRT and add Prevx to be sure that he is gone.
    (If Rootkits run UnHackMe)

    Download - SAVE - go to where you put it-right on - click RUN AS ADMIN

    Malwarebytes - free
    http://www.Malwarebytes.org/

    Run the malware removal tool from Microsoft

    Start - type in the search box-> find MRT top - right on - click RUN AS ADMIN.

    You should get this tool and its updates via Windows updates - if necessary, you can
    Download it here.

    Download - SAVE - go to where you put it-right on - click RUN AS ADMIN
    (Then run MRT as shown above.)

    Microsoft Malicious - 32-bit removal tool
    http://www.Microsoft.com/downloads/details.aspx?FamilyId=AD724AE0-E72D-4F54-9AB3-75B8EB148356&displaylang=en

    Microsoft Malicious removal tool - 64 bit
    http://www.Microsoft.com/downloads/details.aspx?FamilyId=585D2BDE-367F-495e-94E7-6349F4EFFC74&displaylang=en

    also install Prevx to be sure that it is all gone.

    Download - SAVE - go to where you put it-right on - click RUN AS ADMIN

    Prevx - Home - free - small, fast, exceptional CLOUD protection, working with others
    security programs. It is a single scanner, VERY EFFICIENT, if it finds something to come back
    here or use Google to see how to remove.
    http://www.prevx.com/   <-->
    http://info.prevx.com/downloadcsi.asp  <-->

    Choice of PCmag editor - Prevx-
    http://www.PCMag.com/Article2/0, 2817,2346862,00.asp

    Try the demo version of Hitman Pro:

    Hitman Pro is a second scanner reviews, designed to save your computer from malicious software
    (viruses, Trojans, rootkits, etc.). who infected your computer despite safe
    what you have done (such as antivirus, firewall, etc.).
    http://www.SurfRight.nl/en/hitmanpro

    --------------------------------------------------------

    If necessary here are some free online scanners to help the

    http://www.eset.com/onlinescan/

    New Vista and Windows 7 version
    http://OneCare.live.com/site/en-us/Center/whatsnew.htm

    Original version
    http://OneCare.live.com/site/en-us/default.htm

    http://www.Kaspersky.com/virusscanner

    Other tests free online
    http://www.Google.com/search?hl=en&source=HP&q=antivirus+free+online+scan&AQ=f&OQ=&AQI=G1

    --------------------------------------------------------

    Also follow these steps for the General corruption of cleaning and repair/replace damaged/missing
    system files.

    Run DiskCleanup - start - all programs - Accessories - System Tools - Disk Cleanup

    Start - type this into the search-> find COMMAND to top box and RIGHT CLICK-
    RUN AS ADMIN

    Enter this at the command prompt - sfc/scannow

    How to analyze the log file entries that the Microsoft Windows Resource Checker
    (SFC.exe) program generates in Windows Vista cbs.log
    http://support.Microsoft.com/kb/928228

    Run checkdisk - schedule it to run at the next startup, then apply OK then restart your way.

    How to run the check disk at startup in Vista
    http://www.Vistax64.com/tutorials/67612-check-disk-Chkdsk.html

    -----------------------------------------------------------------------

    If we find Rootkits use this thread and other suggestions. (Run UnHackMe)

    http://social.answers.Microsoft.com/forums/en-us/InternetExplorer/thread/a8f665f0-C793-441A-a5b9-54b7e1e7a5a4/

    I hope this helps.

  • I clicked on the source page and remove nodes with the web developer and removal became permanent. EBay does not load pictures. How to fix?

    The problem is on my desktop and my laptop. I got a little happy click on my desktop and click the Web Developer. I tried to remove an ad really annoying flash on the side of the screen. I think I entered in the source page and remove the node. I really don't know what happened, but stopped loading for ebay pictures and everything is a list written on the side of the page. I deleted the cache and cookies. I have reset mozilla. I uninstalled and reinstalled mozilla. Laptop is not immediately affected, but now having the same problem.

    It is a very strange problem.

    Any changes made with the web developer tool will save and should be cleared when the page is reloaded.

    Try disabling graphics hardware acceleration. As this feature has been added to Firefox, it has gradually improved, but there are still some problems.

    You will have to perhaps restart Firefox for it to take effect, so save any work first (e.g. you compose mail, documents online that you are editing, etc.).

    Then perform the following steps:

    • Click on the orange top left Firefox button, then select the 'Options' button, or, if there is no Firefox button at the top, go to tools > Options.
    • In the Firefox options window, click the Advanced tab, and then select 'General '.
    • You will find in the list of parameters, the checkbox use hardware acceleration when available . Clear this check box.
    • Now restart Firefox and see if the problems persist.

    In addition, please check the updates for your graphics driver by following the steps in the following knowledge base articles:

    This solve your problems? The report please come back shortly.

  • I returned my iPhone5 to factory default and gave it to my granddaughter.  She wants to download games etc but the itunes store guard asking my ID and PW.  How can she save herself?  I received and email to say that PW tried to reset

    I returned my iPhone5 to factory default and gave it to my grand daughter as a Christmas gift.

    • She wants to download games etc but the itunes store guard asking my ID and PW.
    • How can she save herself?
    • I received and Apple to say that someone had tried to reset my password by e-mail.
    • It is probably her mother because she also asked me to tell him my PW and ID.
    • I currently use my PW and ID on my new 1Phone6 and do not want to share this.

    Can you please help.

    Julie Bateman

    She needs to log out of your Apple ID in the store and just connect with hers. Go to settings, iTunes and App Store and tap on the Apple ID, then select Disconnect.

  • Requirement of DNS and DHCP Server Essentials 2012 home

    I have a Server Windows Essentials 2012 acting as DNS and DHCP server with a domain name for backups etc on my home network. It's that everything works fine, no errors, no problem. Works well actually, telling me when the children did not install updates or restarted.

    I have two groups of users. My sons step, 10 and 12, which I want to use OpenDNS as a provider external DNS with a policy very, very limited and my wife and me who want to use indications of root or Google DNS or any other DNS provider. Others, specific devices no user (box of the xBox, WII, Satellite, TV, CCTV etc.) can use.

    Before the 2012 server, I had a 2 k 3 server running in a virtual machine for DHCP, alone and put my wife and my devices on static reservations with the just and external DNS provider used OpenDNS as the default scope, DNS. Unfortunately different bits of domain services 2012 don't seem to work unless the server of 2012 is the first DNS server listed on client machines (backups failed. Impossible to find other local computers). Currently, this means that we are all using OpenDNS.

    What I would like is a way to say 2012 to send adult group DNS queries to another DNS provider and leave the rest at default to OpenDNS, while still having them register in the original DNS domain. Any suggestions?

    This issue is beyond the scope of this site and must be placed on Technet or MSDN

    http://social.msdn.Microsoft.com/forums/en-us/home

  • My computer guard restarting itself over and over after windows xp screens.

    My computer guard restarting itself over and over after windows xp screens. He did the same when I try to put it in safe mode. Is it that I can do to get at least pass this screen?

    Kheta salvation,

    1. Did you the latest changes on the computer?
    2. You receive an error message?
    3. When was the last time it was working fine?

    Start the computer by using the option disable automatic system error reboot and check if you receive the error message, and post back with the details.

    1. Restart the computer.
    2. As the computer restarts, press the F8 key repeatedly until you see the Windows Advanced Options screen.
    3. Use the arrow keys to select disable automatic system error reboot and press ENTER.

    If you do not receive the windows logon screen, then refer to the article below and try the steps mentioned.

    Windows XP logon screen does not appear and the computer continuously restarts

    http://support.Microsoft.com/kb/310396

  • The installation source for this product is not available, ensure that the source exists and you can access (to remove Microsoft silverlight)

    I need to install Microsoft silverlight to watch films from netflix, but it is impossible to install it; but in my programs, I have microsoft silverlight (old), I think that if I remove the old program, the new microsoft silverlight will be possible to insall it. The problem is when I try to remove the old silverlight (add or remove programs) do not remove and displays this dialog box "the installation source for this product is not available. Verify that the source exists and that you can access. I like you would help me in this matter. Thank you very much. Manuel Ortega.

    Hello

    I recommend you to ask your question in the Microsoft's Silverlight Installation and Setup forum for better support.

  • Uninstalling Silverlight gives "the installation source for this product is not available. Varify that the source exists and that you can access. »

    I can't remove Silverlight.

    I want to update to Silverlight. When I try to download, the download fails and I get a message to uninstall the old version.  When I try to do, I get a message that says "the installation source for this product is not available. Varify that the source exists and that you can access. »

    I have been in this situation and tried the solution here:

    "How to manually clean a broken Silverlight installation.

    Who has not completely worked for me, however, if I pulled upward from Regedit
    (Start-> Run-> 'Regedit')
    and searched the whole registry "Silverlight", deleting keys of parenthood which contain this string. (There was a large number of them).  When I did, I was finally able to reinstall Silverlight.

    Note that editing the registry is dangerous, so make sure that you first create a backup of the registry and know how to restore it in case things go very wrong.
    "How do back up and restore the registry in Windows XP"
      <>http://support.Microsoft.com/kb/322756 >

    HTH,
    JW

  • Problem uninstalling the program "installation source for this product is not available. Verify that the source exists and that you can access.

    OK, Windows Vista. Try to uninstall unused programs, (SimsLife) and met with the message: "the installation source for this product is not available.  Verify that the source exists and that you can access.  I'm trying to UNINSTALL a product that exists. How to find the source in order to uninstall the program?

    Hello

    Sometimes when you uninstall programs it may be other applications of the dependent files.  Some programs will leave them behind and others will take all during the uninstallation.

    Troubleshoot installing or uninstalling programs

    http://Windows.Microsoft.com/en-us/Windows-Vista/Troubleshoot-installing-or-uninstalling-programs

    Download the free version of CCleaner and use the uninstaller to uninstall the application

    http://www.Piriform.com/ccleaner/download

  • WMM edition error message - ' cannot publish to the specified location. Check the source files and the location is still available and that there is enough disk space. »

    I made a movie of 30 minutes or more in WMM, some of the videos that I imported I had to convert to wmv, to import into WMM. Once I went to publish the movie, after the publication of about 1%, an error message pops up saying something like "cannot publish to the specified location. Check the source files and the location is still available and that there is enough disk space. "I have 8 GB of free space on my hard drive and I tried to burn a cd on a dvd, and save to memory stick, none of them have worked, the same message is displayed even if they have sufficient space available. There is no red x in the videos or photos that I imported, so no files are missing. Some files have been moved when they were converted, but the movie plays well in WMM.  I want to export to is in my documents is therefore always available. I spent hours trying to figure this out and I I still don't know what the problem with it! Help! I've also spent a lot of time to their conversion to avi to see if this helped and the same message appeared again.

    What is the format of your source of debtor files and how did you convert
    TO WMV?

    I can only imagine that you are using Vista Movie Maker 6?

    It's not really about the location... error messages can be very cryptic...
    The error that you mentioned usually appears when the source files in the project
    are damaged or are not fully compatible with Movie Maker and made
    in a movie file cannot continue. In addition, large complex projects can cause
    in this issue.

    In some cases, it may be possible to record in DV - AVI, during registration as
    . WMV fails: the following article explains how to save... Publish it in film...
    6 machine and the graphic link shows where the option:

    Windows Vista - publish a movie in Windows Movie Maker
    http://Windows.Microsoft.com/en-us/Windows-Vista/publish-a-movie-in-Windows-Movie-Maker

    The following chart shows where the DV - AVI option.
    http://www.Papajohn.org/IMGs/Vista-PublishToComputerChoices.jpg

    If the recording as long as DV - AVI fails... see the following articles:

    Movie Maker - problem resolution - "cannot record a movie.
    http://www.Papajohn.org/MovieMaker-issues-CantSaveMovie.html

    Windows Movie Maker error
    Cannot complete the Save Movie Wizard
    http://moviemakererror.blogspot.com/

    Several formats are apparently compatible with
    Movie Maker, but the most reliable choices are:

    Photos - bmp
    Video - wmv
    Audio - wav, wma, wmv

    Sometimes, it can help if you are going to... Tools / Options / Compatibility tab...
    and uncheck all filters.

  • Uninstalling Java problem: "the installation source for this product is not available. Make sure the source exsists and that you can access. »

    Hi, I'm having a little trouble trying to uninstall Java, so I can reinstall it. I get this error message:

    "The installation source for this product is not available. Make sure the source exsists and that you can access. "When I try to find the installation package to uninstall. I'm the only person on my laptop Windows Vista Ultimate, and I am the administrator on the computer. I can't find something when I search for it during the uninstallation. When I go on ' computer > disc Local (c) > Progam Files > Java' I see a whole bunch of files, but I can't find the installation package with the 'Installation .msi package' at the end. I find 'install.rdf '.

    I was wondering if anyone can help find me the source for Java, so I can uninstall and reinstall so my Java work properly.

    Java has been uninstalled before when Elluminate program my brother (online meetings of his school) and I guess when he was relocated something went wrong, but I have 2 Java programs. One by one by Sun Microsystems Inc. and Oracle and I am trying to install are Sun Microsystems Inc..

    Help, please!

    Corky (Corkster)

    Java issues are best handled by people in the Java forum:

    http://Java.com/en/download/help/index_installing.XML?user_os=Vista

    http://Java.com/en/download/help/index.XML For the benefits of others looking for answers, please mark as answer suggestion if it solves your problem.

  • Where should I contact regarding the functions of newsgroups in Windows Mail and Windows Live Mail?

    Where should I contact regarding the functions of newsgroups in Windows Mail and Windows Live Mail?

    I seem to have problems with Windows Mail, perhaps caused by the update KB978542 and/or run the program WMUtil.

    One of my Windows Vista Home Premium SP2 64-bit machines, whenever I try to start Windows Mail, it displays 0x800C0155 error message, then a message saying that he was unable to start because MSOE. DLL could not be initialized.

    The other has problems of material type instead: it's a laptop with no mouse and no reliable connection to the internet.

    On my Windows Vista Home Premium SP2 32-bit machine, I can start Windows Mail, but most local issues have disappeared - only the Inbox is visible.  I already checked that subdirectories for the other files are still present.

    All three of these machines have had problems of backups for months and have had no successful backup for the last two months.

    I have trouble finding enough information about Windows Live Mail without having to install this program if it could avoid these problems or just make it worse.

    http://www.Vistax64.com/tutorials/62560-Windows-Mail-problems.html

    The link above covers solutions to many problems with Windows Mail.

    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

    «The other has problems of material type instead - it's a laptop without mouse and reliable connection to the internet.»

    A computer repair shop will help you with hardware problems.

    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

    http://www.google.com.au/search?hl=en&q=Windows+Live+Mail&btnG=Search&aq=f&aqi=G2G-c1g7&AQL=&OQ=&gs_rfai=

    Read the info at Google re Windows Live Mail.

    See you soon.

    Mick Murphy - Microsoft partner

  • WLC primary and secondary - Config DHCP Scope

    Hi all

    WLCs: AIR-CT2504-K9

    We have therefore two 2504 s each in separate locations. Inside of each of the Access Points, we have configured one of the controllers of the WLC primary and the other as the secondary WLC tab HA. So my question has to do with the internal DHCP configured in each of the controllers scope.

    We only use the internal DHCP server of the WLCs for our Public Wi - Fi network. And I was wondering if I should configure the DHCP scope even in two controllers, or if they are supposed to be different?

    For example:

    Elementary WLC - extended DHCP: 10.12.202.110 - 10.12.202.200
    Secondary WLC - extended DHCP: 10.12.202.xxx - 10.12.202.xxx?

    The way in which access points are configured, they should only be attached to a controller or another. So that the way its set up it shouldn't be some APs on a single controller and some of the other. They should all be attached to the WLC even at any time. So, given that I can configure the same scope on both controllers?

    Any ideas or suggestions would be greatly appreciated!

    Thanks in advance,
    Matt

    Yes, you can set up this way, as long as you don't expect not so much operational WLC & customer service at the same time.

    If you think to expand this network of comments, I suggest you stay away from using DHCP internal like these WLCs has ever made to use as complete apart from entire DHCP servers in large scale networks.

    HTH

    Rasika

    Pls note all useful responses *.

  • L3 - SG300 - 28 p and DHCP

    Hi all

    I'm having a bit of difficulty up a SG300 - 28 p to L3 and DHCP. I will attach a basic network diagram and a very short list of my needs.

    I'm building a temporary network for a company event 1 day that I can't make it work in our office "Lab".

    L3 - SG300 - 28 p connects to our provider using a connection of the SFP.

    I have to be able to address IP DHCP 300 + using the SG300 - 28 p

    My problem is that I can ping my 2 machines test (manually configured IP) about 172.16.0.3 and 172.16.0.4, but cannot ping after the (internet) referral. Also DHCP distributes no intellectual property for the range 172.16.0.10 - 172.16.1.200

    VLAN 1 is set to 10.2.2.20 access port (to the provider through a connection on port 28 FPS)

    VLAN 100 is 172.16.0.2 access port (ports 1-26)

    I have the WLC and WAP tri...

    Is the set of even possible? I know that the EQ network is a bit budget for users, but for a one day business event I just do not have a budget for the purchase of switches better.

    Please excuse the gross chart.

    Thank you in advance.

    -RJ

    Thanks for the reply.

    With the information that you have provided, it seems the only part missing is the way return the unit for service providers. Unfortunately there is no way around that, and no, you will not be able to put anything between the two, because the device doing the NATting is unity of suppliers.

    I think that what is happening is that traffic is actually the side provider, but there is no way to do so as soon as the provider is not a route for the subnet in 172.16.x.x.

    Out of curiosity, why do you use a VLAN for the devices connected to the SG300? Could you use the 10 subnet Ip addresses? If you do this, you will not need to have a route back from the supplier, as all devices will be on the same subnet.

Maybe you are looking for