Changeoption82
option82 时间:2021-04-04 阅读:(
)
2009InfosysTechnologiesLimitedSANOGXIV2009InfosysTechnologiesLimitedSANOGXIVTacklingSpoofingAttacksinBroadbandAccessNetworksBharatJoshi(bharat_joshi@infosys.
com)PavanKurapati(pavan_kurapati@infosys.
com)RamakrishnaRaoDTV(ramakrishnadtv@infosys.
com)2009InfosysTechnologiesLimitedSANOGXIVAgendaSpoofing–What,WhyandHowTypesofuserconnectionsinBroadbandAccessConcentratorsTypesofspoofingHowtocollectdatatodoAnti-spoofinginAccessNetworkAnti-spoofingHowtorecoveranti-spoofingdataafterBACcrash/reboot2009InfosysTechnologiesLimitedSANOGXIVWhatisSpoofiingSpoofingisaprocesswherebyoneentitymasqueradesasanotherentityWhyisspoofingdoneSpoofingAbyBisdoneforvariouspurposesBseekstheprivilegesofABintendstohideitstracksAsanattackonAHowisspoofingdoneWeshallseeincomingslides2009InfosysTechnologiesLimitedSANOGXIVTheultimategoalofspoofingUnauthorizedServiceGetserviceonsomeoneelse'sexpenseLossofServiceonTargetMakesurethatthetargetdoesnotgetanyserviceDifficulttotracetheattackerMakesurethatpeoplecannotfindwhoattackedthem.
UnnecessarypacketscloggingthenetworkMakesurethatnobodygetsagoodservice.
SecondaryvictimPrimarytargetrespondstospoofpacketandoverwhelmthesourcewhichbecomessecondaryvictim.
2009InfosysTechnologiesLimitedSANOGXIVTypesofuserconnectionsforanIPbasedDSLAMBridgedIPRoutingRFC2684basedbridgedencapsulationbetweenEndUserandDSLAMDSLAMinroutingmodewithroutedVLANsconfiguredonuplinki/fDynamicIPallocationusingDHCPPPPoE/APPPterminationinDSLAMIPallocationfromlocalpoolDSLAMinroutingmodewithroutedVLANsconfiguredonuplinki/fIPoARFC2684basedroutedencapsulationbetweenEndUserandDSLAMDSLAMinroutingmodewithroutedVLANsconfiguredonuplinki/fDynamicIPallocationusingDHCPL3DSLAMxDSLHomeHubxDSLHomeHubMPLSCloudPEPRouterPRouterBRASL3n/wDataCenterL3DSLAMInternetservices2009InfosysTechnologiesLimitedSANOGXIV6DSLAML3AxDSLHomeHubL3n/wDHCP2UnicastDISCOVER+Option82populatedwithRemote-ID/Circuit-ID1BroadcastDHCPDISCOVERUnicastDHCPOFFERwithoption82echoed3SendDHCPOFFERtothehostafterremovingoption8246UnicastREQUEST+Option82populatedwithRemote-ID/Circuit-ID5BroadcastDHCPREQUESTUnicastDHCPACKtotheclientwithoption827SendDHCPACKtothehostafterremovingoption828AddressallocationmechanismsforIPDSLAM–DHCP2009InfosysTechnologiesLimitedSANOGXIVTypesofuserconnectionsforaLayer2DSLAM1:1VLANsMapeveryuserconnectiontooneunique802.
1qbasedVLANNoneedofanyMAClearningofindividualhostsDownstreamtrafficmappingdonebasedonVLANsQinQorStackedVLANsAnouterServiceVLANidentifyingaspecificserviceisaddedDownstreammappingdonebasedoncombinationofCVLANandSVLANN:1TransparentBridgedVLANsMultipleusersmappedtoacommonVLANDownstreammappingdonebasedonVLANandDstMACcombinationMAClearningisrequiredforoperationL2DSLAMxDSLHomeHubxDSLHomeHubMPLSCloudPEPRouterPRouterBRASAccessAggregationDataCenterL2DSLAMInternetservices2009InfosysTechnologiesLimitedSANOGXIV8DSLAML2RAxDSLHomeHubBRASL3RAMetroDHCP2BroadcastDISCOVER+Option82populatedwithRemote-ID/Circuit-ID1BroadcastDHCPDISCOVER3UnicastDISCOVERwith'giaddr'populatedUnicastDHCPOFFERwithoption82echoed45BroadcastDHCPOFFERwithoption82andwithout'giaddr'SendDHCPOFFERtothehostafterremovingoption8268BroadcastREQUEST+Option82populatedwithRemote-ID/Circuit-ID7BroadcastDHCPREQUEST9UnicastREQUESTwith'giaddr'populatedUnicastDHCPACKtotheclientwithoption8210SendDHCPACKtothehostafterremovingoption8211AddressallocationmechanismsforL2DSLAM–DHCP2009InfosysTechnologiesLimitedSANOGXIV9DSLAML2RAxDSLHomeHubBRASL3RAMetroDHCPRADIUSPortEnabled1EAPOLStart2IdentityRequest3IdentityResponse4IdentityDetails5EAPMD5Challenge6MD5ChallengeResponse7AuthSuccess8AuthSuccess9DHCPAuthentication&AddressallocationmechanismsforL2DSLAM–DHCP+802.
1x2009InfosysTechnologiesLimitedSANOGXIV10DSLAMxDSLHomeHubBRASMetroRADIUS2PADI+IntermediateAgentpopulatedwithRemote-ID/Circuit-ID1PADIPADO+IntermediateAgentechoed35PADR6PADR+IntermediateAgentpopulatedwithRemote-ID/Circuit-IDPADS+IntermediateAgentechoed79PPPNegotiationsAuthentication&AddressallocationmechanismsforL2DSLAM-PPPoEPADOafterremovingagentinformationoption4PADSafterremovingagentinformationoption82009InfosysTechnologiesLimitedSANOGXIVTypeofSpoofingMACSpoofingIPSpoofingARPSpoofingControlprotocolinternalheaderspoofingPPPoEsession-idspoofingDHCPchaddr,ciaddr,relay-agent-informationoptionspoofing2009InfosysTechnologiesLimitedSANOGXIV12DSLAMAttackerChangeSrcMACaddressandfloodtrafficSimulates1000sofMACaddressatfasterratexDSLMACTablemaximumlimitreachedLegitimatetrafficdroppedduetoMACtableexhaustionChangingSourceMACaddresstoanillegitimateaddressAttackerxDSLMACI/FB2A2FloodtrafficwithbothMACAandMACBMACBLegitimatetrafficblockedMACAMACspoofing2009InfosysTechnologiesLimitedSANOGXIVIPspoofingChangingSourceIPaddresstoanillegitimateaddressAttackerxDSLIPBDoSattackonIPAIPASendtrafficwithIPAandMACBRepliesfloodedtoIPA12PingofDeathServiceProvider'sNetwork2009InfosysTechnologiesLimitedSANOGXIVARPspoofingRespond/sendARPResponsewithillegitimateIPaddressABCDARP:WhoisIPB1ARPReply:IamIPB:MACA2IPMACAABATrafficflowingtohostAARPTableABCDGratuitousARP:IamIPB:MACA1IPMACAABATrafficflowingtohostAARPTableServiceProvider'sNetworkServiceProvider'sNetwork2009InfosysTechnologiesLimitedSANOGXIVDHCPHeaderDHCPHeaderspoofingOp(1)Htype(1)Hlen(1)Hops(1)Xid(4)Secs(2)Flags(2)Ciaddr(4)Yiaddr(4)Siaddr(4)Giaddr(4)Chaddr(16)Sname(64)File(128)Options(Variable)ClientIdenrtifierRelayAgentOptionDSLAMAttackerxDSLL2RAL3RADHCPServerABDHCPRelease:MACB:SrcIP:BChaddr:A2Spoof'chaddr'fieldDHCPRelease:MACB:SrcIP:BClientId:A3Spoof'ClientIdentifier'fieldDHCPRelease:MACB:SrcIP:BOption82RemoteId:A4SpoofOption82fieldChangingInternalfieldswithinDHCPheaderDHCPRelease:MACB:SrcIP:BCiaddr:A1Spoof'ciaddr'field2009InfosysTechnologiesLimitedSANOGXIVSimilarlyPPPoESession-IDfieldidentifiesauniquesession.
SpoofingthiscanalsocauseservicedisruptionPPPoEHeaderPPPoEHeaderspoofingVERTYPECODESESSION_IDLENGTHPAYLOADChangingSESSION_IDfieldinPPPoEHeaderAttackerxDSLIPBIPAPPPoEIABRAS1PADT:SESSION_ID:ASessionDisconnectedServiceProvider'sNetwork2009InfosysTechnologiesLimitedSANOGXIVAnti-spoofingWhatisanti-spoofingMechanismtoidentifyspoofingandstoppingit.
Howanti-spoofingisdoneBydroppingthespoofedpacketsHowtoidentifythespoofedpacketsByverifyingIPAddressofthereceivedpacket.
ByverifyingMACaddressofthereceivedpacket.
ByverifyingthecombinationofIPandMACaddressforagiveninterfaceByverifyingtheIPaddress,MACaddressandothersessionbasedidentificationintheprotocolheader.
2009InfosysTechnologiesLimitedSANOGXIVDatarequiredforAnti-spoofingForeachuserconnectionListofValidIPaddressesassignedListofValidMACaddressesandifpossiblethecombinationofMACandIPaddresses,TimeforwhicheachIPaddressisvalid.
2009InfosysTechnologiesLimitedSANOGXIVWhyanti-spoofinginBroadbandAccessConcentrator(BAC)BACisattherightplace:Itknowsalltherequiredinformationtodoanti-spoofing.
Anti-spoofingbecomesdifficultandlesseffectiveifitisnotdoneasnearthesourceaspossible.
Itisnotonlyimportanttodropspoofedpackets,itisimportanttodropthemasearlyaspossible.
2009InfosysTechnologiesLimitedSANOGXIVDatacollectionforAntispoofinginBAC-PPPoE1xDSLHomeHubBRASL3RAMetroRADIUS2PADIPADO34PADRPADSBACObtainSession-IDfromPADSIPMACSession-IDI/FAA1011BB1022PPPLCPPPPIPCPBACObtainIPinformationfromIPCP567PADTBACDeletethespoofingentry2009InfosysTechnologiesLimitedSANOGXIVDatacollectionforAntispoofinginBAC-DHCPxDSLHomeHubBRASL3RAMetroDHCPIPMACLeaseI/FAA2001BB120212DHCPDISCOVERDHCPOFFER34DHCPREQUESTDHCPACKBACObtainIP/MAC/LeasetimefromDHCPACKMessage6DHCPRELEASEBACRemovetheentryfromtableLeaseEXPIREBACRemovetheentryfromtable2009InfosysTechnologiesLimitedSANOGXIVDatacollectionforAntispoofinginBAC–802.
1x+DHCP1xDSLHomeHubBRASL3RAMetroDHCP2InitialEAPNegotiationsEAPAuthSuccess34DHCPMessageexchangeDHCPACKBACObtaintheMACaddressfromEAPAuthSuccessmessageIPMACLeaseI/FAA2001BB1202RADIUSBACObtainIP&LeasetimefromDHCPACKMessage2009InfosysTechnologiesLimitedSANOGXIVMACAntispoofingDSLAMAttackerAttackerxDSLMACI/FB2A1FloodtrafficwithbothMACAandMACBMACBNoImpactonAMACAMACBIPMACLeaseI/FBB1202Floodtrafficwith1000'sofSrcMACsinadditiontoMACBCompareAntispooftableanddiscardnonmatchingentriesNoMACtableExhaustion!
MACI/FB2MACTableAntiSpoofTableIPMACLeaseI/FAA2001BB1202CompareAntispooftableanddiscardnonmatchingentriesNospoofingofNeighbor'sMAC!
2009InfosysTechnologiesLimitedSANOGXIVIPAntispoofingAttackerxDSLIPBNoImpactonAIPASendtrafficwithIPAandMACB1IPMACLeaseI/FAA2001BB1202CompareIPagainstthei/finAntispooftableMetro2009InfosysTechnologiesLimitedSANOGXIVARPAntispoofingABCDARP:WhoisIPB1ARPReply:IamIPB:MACA2IPMACAABBARPTableABCDGratuitousARP:IamIPB:MACA1IPMACAABBARPTableIPMACLeaseI/FAA2001BB1202CompareIP/MACagainstthei/finAntispooftableIPMACLeaseI/FAA2001BB1202ServiceProviderN/wServiceProviderN/w2009InfosysTechnologiesLimitedSANOGXIVDHCPHeaderAntispoofingDSLAMAttackerxDSLL2RAL3RADHCPServerABDHCPRelease:MACB:SrcIP:BChaddr:A1AntiSpooffilterdiscardDHCPRelease:MACB:SrcIP:BOption82RemoteId:A3Option82fromuntrustedentity.
DiscardIPMACLeaseI/FAA2001BB1202InspectDHCPHeader&comparechaddr&ClientIDwithantispooftableAcceptDHCPwithoption82onlyifitiscomingfromtrustedentityDHCPRelease:MACB:SrcIP:BCiaddr:A2AntiSpooffilterdiscard2009InfosysTechnologiesLimitedSANOGXIVPPPoEHeaderAntispoofingAttackerxDSLIPBIPAPPPoEIABRAS1PADT:SESSION_ID:101IPMACSession-IDI/FAA1011BB1022SessionIDdoesnotmatchNoImpactonAMetro2009InfosysTechnologiesLimitedSANOGXIVLosingdatacollectedforanti-spoofingDatausedinAntispoofingcanbelostduetovariousreasonsPlannedrebootSoftwarecrashPowerfailureReplacementofsystemSoftwareupgrade2009InfosysTechnologiesLimitedSANOGXIVHowtorecoverlostdataStaticconfigurationRequiredDataisavailableintheconfiguration.
PPPoEForPPPoE,thekeep-alivetimersareconfiguredandthesessionisre-initiatediftherearenorepliestothekeep-alivemessagesDHCPDHCPdoesnothavekeepalivemechanisminplace.
DHCPhasa'leasetime'whichisusuallyinorderof'days'.
Howtorecoverfromthissituation2009InfosysTechnologiesLimitedSANOGXIVRecoveringLeaseinformationforDHCPStableStorage:NotveryusefulasnotmanyBACssupportstablestorage.
LimitederasecyclesisalsoabottleneckinthisapproachBroadcastARPs:NeedtowaitfordownstreamtraffictoarriveandinitiateARPrequests.
Willincreasethedelay.
Cannotgetthecompleteinformationinonerequest.
PronetospoofingattacksifamalicioususerrepliestotheARPrequest.
RedundantcontrollersBACcanhaveredundantcontrollersandupononecontrollercrash,theothercontrollercantakeoverwithpre-synchedleasedata.
Notsuitableforpowerfailurescenariosorforupgrades.
Havingredundantcontrollersalsoaddtohardwarecosts2009InfosysTechnologiesLimitedSANOGXIVRecoveringLeaseinformationforDHCPQuerythroughSNMP/LDAPCurrentlynostandardMIBsareavailableforDHCPleaseinformation.
BACstypicallydonotsupportSNMPclientinterfacesQueryleaseinformationfromDHCPserverSolvesmostoftheproblemsstatedabove2009InfosysTechnologiesLimitedSANOGXIVLeasequeryforDHCP(RFC4388)RFC4388introducedanewDHCPrequestLeasequerywhichaBACcanusetoqueryDHCPservertoobtainleaseinformation.
ThreetypesofqueriesaresupportedQuerybyIPaddressOnlyIPaddressispopulatedinthequerymessage.
QuerybyMACaddressOnlyMACaddressispopulatedinthequerymessage.
Ifmorethanoneleaseisavailable,thencorrespondingIPaddressesarereturnedinassociated-ipoption.
BACthengetsadditionaldatabygeneratingquerybyIPaddress.
QuerybyClientidentifierOnlyclientidentifieroptionispopulatedinthequerymessage.
Ifmorethanoneleaseisavailable,thencorrespondingIPaddressesarereturnedinassociated-ipoption.
BACthengetstheadditionaldatabyqueryingbyIPaddress.
2009InfosysTechnologiesLimitedSANOGXIVLeasequeryforDHCP(RFC4388)Threetypesofreplymessagetypesareintroduced:DHCPLEASEACTIVEWhenDHCPserverknowsaboutthequeryidentifier.
DHCPLEASEUNKNOWN:WhenDHCPserverdoesnotknowaboutthequeryidentifier.
AnAccessConcentratorcachethisinformationsothatthiscanbeusedtoavoidgeneratingLeaseQueryforthequeryidentifier.
ThisisknownasNegativeCaching.
DHCPLEASEUNASSIGNED:WhenDHCPserverdoesmanagethequeryidentifierbutnoleaseisyetassigned.
NegativeCachingisdoneforthisresponseaswell.
2009InfosysTechnologiesLimitedSANOGXIVRFC4388basedleasequery–DataDriven34DSLAMLayer3RelayAgentxDSLHomeHubServiceProviderNetworkDHCPServerM1192.
168.
1.
2T1I1M2192.
168.
1.
8T2I1MACIPLeaseI/fM1192.
168.
1.
2T1I1AntiSpoofTable123I12009InfosysTechnologiesLimitedSANOGXIVRFC4388basedleasequery–DataDriven35DSLAMLayer3RelayAgentxDSLHomeHubServiceProviderNetworkDHCPServerCRASHMACIPLeaseI/fAntiSpoofTable123I12009InfosysTechnologiesLimitedSANOGXIVRFC4388basedleasequery–DataDriven36DSLAMLayer3RelayAgentxDSLHomeHubServiceProviderNetworkDHCPServer1DataTrafficfrom192.
168.
1.
22LeaseQuerybyIPAddress3LeaseActiveM1,T1,I1MACIPLeaseI/fM1192.
168.
1.
2T1I1AntiSpoofTable4DataTrafficfrom192.
168.
1.
25123I12009InfosysTechnologiesLimitedSANOGXIVRFC4388basedleasequery–NegativeCaching37xDSLHomeHubServiceProviderNetworkDHCPServerCRASH123I12009InfosysTechnologiesLimitedSANOGXIVRFC4388basedleasequery–NegativeCaching381DataTrafficfrom192.
168.
1.
102LeaseQuerybyIPAddressNegativeCachingxDSLHomeHubServiceProviderNetworkDHCPServer123MACIPThresholdI/fM1192.
168.
1.
10T1I13LeaseUNKNOWN182.
168.
1.
10,M14I12009InfosysTechnologiesLimitedSANOGXIVRFC4388basedleasequery–NegativeCaching392DataTrafficfrom192.
168.
1.
103LeaseQuerybyIPAddressNegativeCachingxDSLHomeHubServiceProviderNetworkDHCPServer123MACIPThresholdI/fM1192.
168.
1.
10T1I14LeaseUNKNOWN182.
168.
1.
10,M1Thresholdexpired1I12009InfosysTechnologiesLimitedSANOGXIVIssueswithRFC4388basedleasequeryExistingLeasequerymechanismisdatadriven:LeasequeryisinitiatedonlywhenAccessConcentratorsreceivesdataExistingmethodsuggeststheuseofnegativecaching.
NegativeCachingconsumeslotofresourcesunderspoofattacks.
Resultsinincreasedoutagetimefortheclients.
2009InfosysTechnologiesLimitedSANOGXIVIssueswithRFC4388basedleasequery(contd.
.
)Gettingconsolidatedleaseinformationperconnectionisnotpossible:Existingmechanismdoesn'thaveanymethodstogetconsolidatedleaseinformationforalltheclientsbelongingtoaconnection/circuitMultipleclientscanresideforagivenconnection/circuit.
IfAccessconcentratorhasleaseinformationofalltheclientsforagivenconnection/circuit,anti-spoofingcanbedoneindataplane(fastpath)2009InfosysTechnologiesLimitedSANOGXIVQuerybyremote-idRemote-IDsuboptionidentifyiesaconnection/circuituniquely.
ThisisgloballyuniqueidentifierRemote-IDcanbetrustedastheyarecreatedbyRelayAgent.
AccessConcentratorneednotwaitforthetraffictoarriveandcangenerateLeaseQueryassoonasitcomesupafterareboot.
DHCPServercanprovideconsolidatedLeaseInformationforaspecificconnection/circuit.
Oncealltheleaseinformationforagivenconnection/circuitisobtained,anti-spoofingcanbedoneindataplane(fastpath).
NoneedforNegativeCaching.
2009InfosysTechnologiesLimitedSANOGXIVLeaseQuerybyRemoteId43xDSLHomeHubServiceProviderNetworkDHCPServer123M1192.
168.
1.
2T1I1M2192.
168.
1.
8T2I1M3192.
168.
1.
10T3I1MACIPLeaseI/fAntiSpoofTableI12009InfosysTechnologiesLimitedSANOGXIVLeaseQuerybyRemoteId44xDSLHomeHubServiceProviderNetworkDHCPServerCRASH123MACIPLeaseI/fAntiSpoofTableI12009InfosysTechnologiesLimitedSANOGXIVLeaseQuerybyRemoteId451LeaseQuerybyRemoteIdforI12LeaseActiveofallthreeleases*3DataTrafficfrom192.
168.
1.
8xDSLHomeHubServiceProviderNetworkDHCPServer123M1192.
168.
1.
2T1I1M2192.
168.
1.
8T2I1M3192.
168.
1.
10T3I1MACIPLeaseI/fAntiSpoofTable4DataTrafficfrom192.
168.
1.
8BACdoesnotneedtowaitforthetraffictoinitiateLQLeasequerybyremote-idresultsinobtainingcompleteinformationonagiveninterface.
NoneedofinitiatingsubsequentqueriesI1*Leaseactiveforoneleaseisreturnedfollowedbyassociated-IPoption.
ThisresultsinsubsequentquerybyIPforremainingleases2009InfosysTechnologiesLimitedSANOGXIVProtocolDetails:ServeridentifiesaLeasequerybyremote-idwhentheleasequerymessagehas:Chaddr,siaddr,Ciaddr,htype,hlenandchaddriszeroandClientidentifieroptionisnotpresentandOption82withonlyRemote-Idsub-optionispresent.
SendsaLEASEACTIVEpopulatingtheciaddrwiththeIPaddressthatwasmostrecentlyaccessedbytheclient.
AllotherIPaddressesarereturnedinAssociated-IPoption.
RelayagentthensendsaLeasequerywith"QuerybyIPAddress"foralltheadditionalIPaddressesreturnedinAssociated-ipoption.
2009InfosysTechnologiesLimitedSANOGXIVProtocolDetails:ServermayreturnaLEASEUNASSIGNEDifitknowsitmanagestheleasefortheconnectionidentifiedbyRemote-Idsub-optionbutnoleaseisassignedyet.
ServermayreturnLEASEUNKNOWNifitdoesnotknowthecorrespondingRemote-idsub-option.
2009InfosysTechnologiesLimitedSANOGXIVWhyBulkLeasequeryTraditionalleasequery(Both4388)andleasequerybyremote-idworksontheprincipleofretrievingoneleaseatatimeWhilequerybyremote-idsolvesalltheproblemsassociatedwithRFC4388basedleasequerymechanism,itstillinvolvesgeneratinghugenumberofleasequeriestogetallthepossibledataBulkleasequeryworksontheprincipleofestablishingTCPconnectionbetweenRAandServerandretrievinginformationinbulk2009InfosysTechnologiesLimitedSANOGXIVBulkLeaseQuery49DSLAMLayer3RelayAgentxDSLHomeHubServiceProviderNetworkDHCPServerMACIPAddressLeaseTimeInterfaceM1192.
168.
1.
2T1I1M2192.
168.
1.
8T2I2M3192.
168.
1.
3T2I3I1I2I32009InfosysTechnologiesLimitedSANOGXIVBulkLeaseQuery50DSLAMLayer3RelayAgentxDSLHomeHubServiceProviderNetworkDHCPServerCRASHI1I2I3MACIPLeaseI/f2009InfosysTechnologiesLimitedSANOGXIVBulkLeaseQuery51DSLAMLayer3RelayAgentxDSLHomeHubServiceProviderNetworkDHCPServerMACIPAddressLeaseTimeInterfaceM1192.
168.
1.
2T1I1M2192.
168.
1.
8T2I2M3192.
168.
1.
3T2I33DataTrafficfrom192.
168.
1.
81BulkLeaseQueryinaTCPSession2LeaseActiveofallleases4DataTrafficfrom192.
168.
1.
8LeaseinformationofallinterfacesobtainedininonequeryI1I2I32009InfosysTechnologiesLimitedSANOGXIVProtocolDetails:DSLAMLayer3RelayAgentxDSLHomeHubServiceProviderNetworkDHCPServer1TCPSession2BulkLeaseQuerywithXID23LEASEQUERYACTIVEforXID24LEASEQUERYACTIVEforXID25LEASEQUERYACTIVEforXID26LEASEQUERYDONEforXID27TCPsessionclose2009InfosysTechnologiesLimitedSANOGXIVProtocolDetails:AQuerier(TypicallyaRelayAgent)establishesaTCPconnectionwiththeserveronport67.
Twonewquerytypesareadded"QuerybyRelay-ID"whererelay-idisauniqueRelayagentIdentifier.
AllleasesallocatedthroughaspecificRelayAgent.
"QueryforallconfiguredIPs"whereallIPaddressheldbyDHCPServerirrespectiveofstateisreturned.
Inthiscase,unassignedIPaddressesarereturnedwithUNASSIGNEDstate.
Newfiltersareadded:StartandEndtimefiltercanbepassedtoretrieveleasesforwhichstatehaschangedwithinthespecifiedtime.
Otherquerytypes(QuerybyIPAddress,MACaddress,Client-IDandremote-id)arealsosupported.
2009InfosysTechnologiesLimitedSANOGXIVProtocolDetails:UponreceivingaBULKLEASEQUERY,DHCPservergeneratesastreamofLEASEACTIVEforeachleasethatfulfilsthequery.
EndofleaseforagivenqueryisindicatedbytheLEASEQUERYDONEmessage.
MultipleBulkLeasequerycanbeinitiatedoverasingleTCPconnection.
Transactionid(XID)isusedtodistinguishbetweentherepliesformultiplequeries.
2009InfosysTechnologiesLimitedSANOGXIVStandardizationandImplementationeffortsStandardizationefforts:Querybyremote-idandBulkLeaseQuerydraftisbeingstandardizedinDHCworkinggroupofIETF.
Implementationefforts:WehavecreatedaProof-Of-Conceptimplementationof'QuerybyRemote-Id'and'BulkLeaseQuery'byenhancingISCDHCPserver.
2009InfosysTechnologiesLimitedSANOGXIVReferences:S.
Bellovin,"SecurityproblemsintheTCP/IPprotocolsuite,"SIGCOMMComputerCommunicationReview,vol.
19,no.
2,pp.
32–48,1989.
R.
BeverlyandS.
Bauer,"Thespooferproject:inferringtheextentofsourceaddressfilteringontheinternet,"inSRUTI'05:Proc.
oftheStepstoReducingUnwantedTrafficontheInternet,2005.
IETFStandards:RFC2131,DynamicHostConfigurationProtocolLayer2RelayAgenthttp://www.
ietf.
org/id/draft-ietf-dhc-l2ra-04.
txthttp://www.
ietf.
org/id/draft-ietf-dhc-l2ra-extensions-01.
txtQuerybyremote-idhttp://www.
ietf.
org/id/draft-ietf-dhc-leasequery-by-remote-id-02.
txtBulkleasequeryhttp://www.
ietf.
org/id/draft-ietf-dhc-dhcpv4-bulk-leasequery-00.
txtTR-101fromBroadbandForumhttp://www.
broadband-forum.
org/technical/download/TR-101.
pdf2009InfosysTechnologiesLimitedSANOGXIV2009InfosysTechnologiesLimitedSANOGXIVThankYou
专心做抗投诉服务器的VirtVPS上线瑞士机房,看中的就是瑞士对隐私的保护,有需要欧洲抗投诉VPS的朋友不要错过了。VirtVPS这次上新的瑞士服务器采用E-2276G处理器,Windows/Linux操作系统可选。VirtVPS成立于2018年,主营荷兰、芬兰、德国、英国机房的离岸虚拟主机托管、VPS、独立服务器、游戏服务器和外汇服务器业务。VirtVPS 提供世界上最全面的安全、完全受保护和私...
易探云怎么样?易探云是目前国内少数优质的香港云服务器服务商家,目前推出多个香港机房的香港云服务器,有新界、九龙、沙田、葵湾等机房,还提供CN2、BGP及CN2三网直连香港云服务器。近年来,许多企业外贸出海会选择香港云服务器来部署自己的外贸网站,使得越来越多的用户会选择易探云作为网站服务提供平台。今天,云服务器网(yuntue.com)小编来谈谈易探云和易探云服务器怎么样?具体香港云服务器多少钱1个...
恒创科技也有暑期的活动,其中香港服务器也有一定折扣,当然是针对新用户的,如果我们还没有注册过或者可以有办法注册到新用户的,可以买他们家的香港服务器活动价格,2M带宽香港云服务器317元。对于一般用途还是够用的。 活动链接:恒创暑期活动爆款活动均是针对新用户的。1、云服务器仅限首次购买恒创科技产品的新用户。1 核 1G 实例规格,单个账户限购 1台;其他活动机型,单个账户限购 3 台(必须在一个订单...
option82为你推荐
openeuler谁知道open opened close closed的区别吗百度关键词价格查询在百度设置关键字是怎么收费的www.jjwxc.net晋江文学网 的网址是什么?郭泊雄郭佰雄最后一次出现是什么时候?www.765.com哪里有免费的电影网站百度指数词百度指数为0的词 为啥排名没有avtt4.comwww.51kao4.com为什么进不去啊?抓站工具大家在家用什么工具练站?怎么固定?面壁思过?在医院是站站立架www.toutoulu.comSEO行业外链怎么做?机器蜘蛛挑战或是生存Boss是一只巨型机器蜘蛛的第一人称射击游戏叫什么
国外虚拟主机 域名到期查询 广州服务器租用 网通服务器租用 樊云 香港主机 10t等于多少g 香港cdn 双12活动 光棍节日志 中国智能物流骨干网 刀片服务器是什么 七夕快乐英文 速度云 中国电信宽带测速网 创建邮箱 万网空间管理 shuang12 智能dns解析 个人免费邮箱 更多