Q17Secure Network Access, Visibility, and Enforcement
An administrator is configuring a DHCP server to improve the security of their environment. They need to rate-limit traffic while ensuring that legitimate requests are not dropped. How can this be accomplished?
← → navigate · a answer
Community votes
Discussion · 24
14
Folks, there are already plenty of wrong answers confirmed and posted by "experts", so there's no point in adding wrong answers ourselves here. You cannot add entries to the DHCP snooping database. That's the wrong answer. The only case where you create a mapping of IP to MAC and VLAN and port is when configuring "ip source guard", but that is not the same as DHCP snooping.
Unless you explicitly set a rate limit on an interface, changing the trust state of the interface also changes its rate limit to the default value for that trust state. After you configure the rate limit, the interface keeps the rate limit even when its trust state changes
https://content.cisco.com/chapter.sjs?uri=/searchable/chapter/www.cisco.com/content/dam/en/us/td/docs/switches/lan/catalyst4500/XE35-0XO/configuration/guide/dhcp.fm/jcr:content/renditions/config_dhcp.html.xml
6
So, it's A ?
2
Answer is C
A 2
Selected Answer: A
I choose "A". The question said "An administrator is configuring a DHCP server", the DHCP server is a new setup, so it should not have trust interface before, we need to set it up once the DHCP server is newly installed.
2
Finally, I choose "C". The rate limiting would not be enabled by default when ip dhcp snooping is configured. However, it will be enabled on untrust interface once the arp inspection is enabled.
2
Vote for A
Ensure that legitimate requests are not dropped (without trusted interface the traffic is dropped).
This will also satisfy the request "able to rate-limit the traffic". "Able to", meaning it can be configured.
2
If you are going to configure DAI (Dynamic ARP Inspection) and IP Source Guard (IPSG) you have to add statically assigned IP addresses to the DHCP snooping database, as DAI and IPSG are using it.
Depending on platform and version, you can add static entries into the DHCP snooping database:
- Router# ip dhcp snooping binding binding_id vlan vlan_id interface interface expiry lease_time
- Switch# ip dhcp snooping binding mac-addr vlan vlan ipaddr interface ifname expiry lease-in-seconds
Please do not call someone "expert" just because you are not.
2
Not a valid comment
You can add entries manually:
Router# ip dhcp snooping binding mac_address vlan vlan_ID ip_address interface ifname expiry lease_in_seconds
eg. https://www.cisco.com/en/US/docs/general/Test/dwerblo/broken_guide/snoodhcp.pdf
command.
2
This answer is A as shown below from the offical cert guide, don't over think it.
The DHCP snooping feature determines whether traffic sources are trusted or untrusted. An
untrusted source may initiate traffic attacks or other hostile actions. To prevent such attacks,
the DHCP snooping feature filters messages and rate-limits traffic from untrusted sources.
The following steps are required to implement DHCP snooping on your network:
Step 1. Define and configure the DHCP server. Configuration of this step does not take
place on the switch or router and is beyond the scope of this book.
Step 2. Enable DHCP snooping globally.
Step 3. Enable DHCP snooping on at least one VLAN. By default, DHCP snooping is
inactive on all VLANs.
Step 4. Ensure that the DHCP server is connected through a trusted interface.
By default, the trust state of all interfaces is untrusted.
Step 5. Configure the DHCP snooping database agent. This step ensures that database
entries are restored after a restart or switchover.
A 2
Selected Answer: A
Basically, DHCP snooping drops DHCP offers on untrusted ports. However, Catalyst switches do not forward DHCP discovers on untrusted ports. If you do not trust the port of the valid DHCP server, then the legitimate discovers will get dropped. That is why I picked A. See source below:
https://networklessons.com/switching/dhcp-snooping
A 2
Selected Answer: A
Answer is A.
C 1
Selected Answer: C
Answer is C
1
D is the correct answer!
A enables trust on the interface connected to the DHCP server. the trust statement has nothng to do with rate limit!
C is also not correct! you can't set rate limit on ARP inpection.
But with D,
Switch(config-if)#ip dhcp snooping limit rate ?
<1-2048> DHCP snooping rate limit
Switch(config-if)#ip dhcp snooping limit rate
1
D is saying to add entries in the DHCP Snooping DB, you're statement is for setting the rate limit? It's still not clear what the answer is here!
C 1
Selected Answer: C
As zheka said, answer is C
C 1
Selected Answer: C
DHCP snooping has no default rate limit
https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst6500/ios/12-2SXF/native/configuration/guide/swcg/snoodhcp.pdf
hence only C make sense
1
ARP inspection rate-limits ARP packets, not DHCP requests. I vote for A
1
Please refer to this video at 13:22
https://www.youtube.com/watch?v=HwbTKaIvL6s&ab_channel=Jeremy%27sITLab
1
Aswer A
The DHCP snooping feature determines whether traffic sources are trusted or untrusted. An untrusted source may initiate traffic attacks or other hostile actions. To prevent such attacks, the DHCP snooping feature filters messages and rate-limits traffic from untrusted sources.
1
Answer is not A, I know because this is one of my few mistakes a couple of days ago. Admin, if you are reading this please give the correct answer and I ask you not to post this comment
C 1
Selected Answer: C
Answer C
1
Correct answer A
Checked with securitytut
D 1
Selected Answer: D
It's possible to do this with D , eg. downloading the snooping database from tftp server (taken from DHCP server)... but cumbersome ... I am not sure if enough answer shall be A
or D ....
source - any IOS , IIS-XE, NX-OS ... DHCP snoopoing config guide ... https://www.cisco.com/c/en/us/td/docs/dcn/nx-os/nexus3548/103x/configuration/security/cisco-nexus-3548-nx-os-security-configuration-guide-103x/m-configuring-dhcp-snooping.pdf
A 1
Selected Answer: A
OCG p. 339. "DHCP Snooping...rate-limits DHCP traffic from trusted and untrusted interfaces."