This topic describes DHCP snooping on the Cisco 8000 Series Router, which enhances network security by preventing unauthorized DHCP servers from distributing IP addresses.
DHCP snooping is a Layer 2 security feature that
-
maintains a list of approved servers so that only trusted DHCP messages are processed,
-
safeguards against IP address spoofing and man-in-the-middle attacks by inspecting and filtering DHCP packets, and
-
integrates with existing network configurations to provide protection while maintaining efficient IP address management.
|
Feature Name |
Release Information |
Feature Description |
|---|---|---|
|
DHCP Snooping |
Release 25.4.1 |
Introduced in this release on: Fixed Systems (8010 [ASIC: A100])(select variants only*) *This feature is supported on:
|
|
DHCP Snooping |
Release 25.1.1 |
Introduced in this release on: Fixed Systems (8010 [ASIC: A100]) This feature is supported on Cisco 8011-4G24Y4H-I routers. |
|
DHCP Snooping |
Release 24.4.1 |
Introduced in this release on: Fixed Systems (8200 [ASIC: P100], 8700 [ASIC: P100, K100])(select variants only*); Modular Systems (8800 [LC ASIC: P100])(select variants only*) DHCP snooping enhances network security and prevents unauthorized or malicious DHCP servers from distributing IP addresses. By maintaining a list of approved servers, DHCP snooping ensures that only trusted DHCP messages are processed. This feature safeguards against IP address spoofing and man-in-the-middle attacks by inspecting and filtering DHCP packets. This reliable security measure integrates seamlessly with existing network configurations, offering robust protection for your network infrastructure while maintaining efficient IP address management. *This feature is supported on:
|
DHCP snooping features are focused on the edge of the aggregation network. Security features are applied at the first point of entry for subscribers. The relay agent information option is used to identify the subscriber's line, which is either the DSL line to the subscriber's home or the first port in the aggregation network.
The central concept for DHCP snooping is that of trusted and untrusted links. A trusted link provides secure access for traffic on that link. On an untrusted link, subscriber identity and subscriber traffic cannot be determined. DHCP snooping runs on untrusted links to provide subscriber identity. The following figure shows an aggregation network. The link from the DSLAM to the aggregation network is untrusted and is the point of presence for DHCP snooping. The links that connect the switches in the aggregation network and the link from the aggregation network to the intelligent edge are considered trusted.
Enabling both DHCP relay on a BVI and DHCP snooping in a bridge domain that has a BVI can result in duplicate DHCP messages from the DHCP client to the DHCP server.