HP 6120XG HP ProCurve Series 6120 Blade Switches Access Security Guide - Page 461

Dynamic Configuration Arbiter DCA, DHCP Option 82

Page 461 highlights

bpdu protection, none ... 1-8 SSH, disabled ... 1-4, 6-2 SSL, disabled ... 1-5, 7-2 TACACS+ authentication configuration ... 4-9 authentication, disabled ... 1-5, 4-2 login attempts, 3 ... 4-6 tacacs-server-timeout, 5 seconds ... 4-23 TCP port number for SSH connections, 22 ... 6-18 TCP port number for SSL connections, 443 ... 7-19 Telnet access, enabled ... 1-4 traffic filters, none ... 9-2 traffic/security filters, none ... 1-7 UDP destination port for accounting, 1813 ... 5-7 UDP destination port for authentication, 1812 ... 5-7 user authentication, disabled ... 6-2 virus throttling, none ... 1-8 Web and MAC authentication ... 3-3-3-54 Web authentication, disabled ... 1-6 Web-browser access, enabled ... 1-4 denial-of-service avoid attacks using DHCP snooping ... 8-4 monitoring system resources ... 8-33 DES ... 7-3 DHCP Option 82 IP-to-MAC binding database ... 8-20, 8-28 DHCP protection See DHCP snooping. DHCP snooping ... 8-4 authorized server ... 8-5 binding database ... 8-12 changing remote-id ... 8-11 configuring authorized server address ... 8-9 database ... 8-5 denial-of-service attack ... 8-4 DHCPACK ... 8-5 DHCPDECLINE ... 8-5 DHCPNACK ... 8-5 DHCPOFFER ... 8-5 DHCPRELEASE ... 8-5 disable MAC check ... 8-11 disabling ... 8-5 dropping packets ... 8-5 enabling ... 8-5 debug logging ... 8-13 on trusted ports ... 8-8 on VLANs ... 8-6, 8-7 IP-to-MAC binding database ... 8-20, 8-28 log messages ... 8-14 Option 82 ... 8-9 option parameter ... 8-6 remote-id ... 8-10 show configuration ... 8-6 stats ... 8-6 trust ... 8-6 untrusted-policy ... 8-10 verify ... 8-6 documentation feature matrix ... -xviii latest versions ... -xvii printed in-box publication ... -xvii release notes ... -xvii duplicate IP address effect on authorized IP managers ... 12-13 dynamic ARP protection additional validation checks on ARP packets ... 8-21 ARP packet debugging ... 8-23 displaying ARP statistics ... 8-22 enabling ... 8-16 IP-to-MAC binding, adding to DHCP database ... 8-20, 8-28 trusted ports, configuring ... 8-18 verifying configuration ... 8-21 Dynamic Configuration Arbiter (DCA) applying settings to non-authenticated clients ... 1-18 hierarchy of precedence in authentication sessions ... 1-19 overview ... 1-17 dynamic IP lockdown debugging ... 8-31 DHCP binding database ... 8-25 DHCP leases ... 8-25 DHCP snooping ... 8-24 enabling ... 8-26 filtering IP addresses ... 8-25 overview ... 8-23 spoofing protection ... 8-24 verifying configuration ... 8-29 VLAN binding ... 8-25 Index - 5

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384
  • 385
  • 386
  • 387
  • 388
  • 389
  • 390
  • 391
  • 392
  • 393
  • 394
  • 395
  • 396
  • 397
  • 398
  • 399
  • 400
  • 401
  • 402
  • 403
  • 404
  • 405
  • 406
  • 407
  • 408
  • 409
  • 410
  • 411
  • 412
  • 413
  • 414
  • 415
  • 416
  • 417
  • 418
  • 419
  • 420
  • 421
  • 422
  • 423
  • 424
  • 425
  • 426
  • 427
  • 428
  • 429
  • 430
  • 431
  • 432
  • 433
  • 434
  • 435
  • 436
  • 437
  • 438
  • 439
  • 440
  • 441
  • 442
  • 443
  • 444
  • 445
  • 446
  • 447
  • 448
  • 449
  • 450
  • 451
  • 452
  • 453
  • 454
  • 455
  • 456
  • 457
  • 458
  • 459
  • 460
  • 461
  • 462
  • 463
  • 464
  • 465
  • 466
  • 467
  • 468
  • 469

Index – 5
bpdu protection,
none
… 1-8
SSH,
disabled
… 1-4, 6-2
SSL,
disabled
… 1-5, 7-2
TACACS+
authentication configuration … 4-9
authentication,
disabled
… 1-5, 4-2
login attempts,
3
… 4-6
tacacs-server-timeout,
5 seconds
… 4-23
TCP port number for SSH connections,
22
… 6-18
TCP port number for SSL connections,
443
… 7-19
Telnet access,
enabled
… 1-4
traffic filters,
none
… 9-2
traffic/security filters,
none
… 1-7
UDP destination port for accounting,
1813
… 5-7
UDP destination port for authentication,
1812
… 5-7
user authentication,
disabled
… 6-2
virus throttling,
none
… 1-8
Web and MAC authentication … 3-3–3-54
Web authentication,
disabled
… 1-6
Web-browser access,
enabled
… 1-4
denial-of-service
avoid attacks using DHCP snooping … 8-4
monitoring system resources … 8-33
DES
… 7-3
DHCP Option 82
IP-to-MAC binding database … 8-20, 8-28
DHCP protection
See
DHCP snooping.
DHCP snooping
… 8-4
authorized server … 8-5
binding database … 8-12
changing remote-id … 8-11
configuring authorized server address … 8-9
database … 8-5
denial-of-service attack … 8-4
DHCPACK … 8-5
DHCPDECLINE … 8-5
DHCPNACK … 8-5
DHCPOFFER … 8-5
DHCPRELEASE … 8-5
disable MAC check … 8-11
disabling … 8-5
dropping packets … 8-5
enabling … 8-5
debug logging … 8-13
on trusted ports … 8-8
on VLANs … 8-6, 8-7
IP-to-MAC binding database … 8-20, 8-28
log messages … 8-14
Option 82 … 8-9
option parameter … 8-6
remote-id … 8-10
show configuration … 8-6
stats … 8-6
trust … 8-6
untrusted-policy … 8-10
verify … 8-6
documentation
feature matrix … -xviii
latest versions … -xvii
printed in-box publication … -xvii
release notes … -xvii
duplicate IP address
effect on authorized IP managers … 12-13
dynamic ARP protection
additional validation checks on ARP
packets … 8-21
ARP packet debugging … 8-23
displaying ARP statistics … 8-22
enabling … 8-16
IP-to-MAC binding, adding to DHCP
database … 8-20, 8-28
trusted ports, configuring … 8-18
verifying configuration … 8-21
Dynamic Configuration Arbiter (DCA)
applying settings to non-authenticated
clients … 1-18
hierarchy of precedence in authentication
sessions … 1-19
overview … 1-17
dynamic IP lockdown
debugging … 8-31
DHCP binding database … 8-25
DHCP leases … 8-25
DHCP snooping … 8-24
enabling … 8-26
filtering IP addresses … 8-25
overview … 8-23
spoofing protection … 8-24
verifying configuration … 8-29
VLAN binding … 8-25