Junos DHCP Snooping and IP Source Guard on EX - 夜莺博客

Junos DHCP Snooping and IP Source Guard on EX

An access switch that accepts any IP address a device claims is an access switch that will eventually be used to spoof one. Juniper EX switches address this with a trio of access-security features that all read from the same place: the DHCP snooping binding table. Once that table is populated, IP source guard filters packets whose source address and MAC do not match a binding, and dynamic ARP inspection does the same for ARP. This article covers the ELS configuration hierarchy, the trust model, and how to verify each feature independently.

The trust model you are configuring

  • Access ports are untrusted by default. A DHCP server response arriving on an access port is dropped — which is the whole point.
  • Trunk ports are trusted by default, so the uplink towards the real DHCP server keeps working.
  • Trust can be overridden per interface by placing the interface in a group with overrides trusted, which is how you handle a DHCP server that is genuinely connected to an access port.
  • IP source guard and ARP inspection only apply to untrusted access interfaces; traffic from trusted interfaces is not checked.

Configuration on an ELS switch (EX2300/EX3400/EX4300 and later)

set vlans DATA vlan-id 10
set vlans DATA interface ge-0/0/1.0

! the port facing the real DHCP server is trusted
set vlans DATA forwarding-options dhcp-security group TRUSTED-SERVERS overrides trusted
set vlans DATA forwarding-options dhcp-security group TRUSTED-SERVERS interface ge-0/0/24.0

! build the binding table, then enforce it
set vlans DATA forwarding-options dhcp-security
set vlans DATA forwarding-options dhcp-security ip-source-guard
set vlans DATA forwarding-options dhcp-security arp-inspection

Enabling dhcp-security on a VLAN is what starts the snooping process and builds the binding table. ip-source-guard and arp-inspection are enforcement layers on top of it — turn them on before the binding table has had time to populate and you will block legitimate hosts, so verify the table first on a live network.

Static bindings for fixed equipment

set vlans DATA forwarding-options dhcp-security group STATIC-HOSTS interface ge-0/0/5.0
set vlans DATA forwarding-options dhcp-security group STATIC-HOSTS interface ge-0/0/5.0 static-ip 10.10.10.50
set vlans DATA forwarding-options dhcp-security group STATIC-HOSTS interface ge-0/0/5.0 mac 00:11:22:33:44:55

Servers, printers and building systems with static addresses never appear in the snooping table, so they need explicit bindings. This is the single most common reason a rollout "breaks the printers" — the fixed-address devices were never accounted for.

Verification

! the binding table - the source of truth for everything else
show dhcp snooping binding
show dhcp-security binding            ! ELS releases

! per-feature statistics
show dhcp-security ip-source-guard statistics
show dhcp-security statistics

! confirm which interfaces the switch considers trusted
show configuration vlans DATA forwarding-options dhcp-security

Read the statistics counters as the pass/fail signal: an incrementing drop counter on an access port means the feature is working and something on that port is misbehaving. If the counters are frozen at zero, the feature is not applied to the interface you think it is — usually because the interface is in a different VLAN or is still trusted.

Symptoms and causes

  • A host cannot get an address at all — its DHCP request is being dropped because the port is trusted when it should not be, or the DHCP server is on an untrusted port. Check the group configuration first.
  • A host gets an address but cannot pass traffic — IP source guard has no binding for it. Usually the host uses a static address, or the binding expired.
  • ARP works but IP does not (or the reverse) — only one of the two enforcement features is enabled; they are independent.
  • Rollout breaks the whole VLAN — features applied before the binding table populated, or trunk ports configured as untrusted by mistake.
  • Bindings disappear after a reboot — the table is built from live snooping; static devices need static bindings to survive.

Rollout order that avoids an outage

  1. Enable dhcp-security only, and watch the binding table fill for a day.
  2. Add static bindings for every fixed-address device you can identify.
  3. Enable ip-source-guard on one access switch, verify, then expand by switch rather than by VLAN across the whole estate at once.
  4. Add arp-inspection last, because ARP problems are the hardest to diagnose from a user report.

Supporting features on the same platform: Junos port security and MAC limiting for the Layer 2 identity side, and Junos firewall filters if you need to filter by address rather than by binding. For the same feature set on other platforms, see Cisco DHCP snooping.

原文链接:https://juniper.net/documentation/us/en/software/junos/security-services/topics/example/port-security-ip-source-guard-plus-other-switch-features.html