Community discussions

MikroTik App
 
User avatar
ekarin
Trainer
Trainer
Topic Author
Posts: 34
Joined: Fri Jun 01, 2018 9:12 pm
Contact:

DHCP Snooping and DHCP Option 82

Sat May 25, 2019 10:46 am

Hello,

With regard to preventing any rogue DHCP servers, I have set up a bridge as well as enabled the DHCP Snooping on it. After that I have enabled the trusted feature on the port that connects to the DHCP server. It works. :-)

What I noticed is that after enabling the DHCP Snooping on the bridge, the Add DHCP option 82 feature appears automatically. I have tested the function of preventing a rogue DHCP server with regard to the Add DHCP option 82 feature. As a result, it works in both scenarios (i.e. with and without the Add DHCP option 82 feature). This means that the Add DHCP option 82 feature is not needed in the function of preventing a rogue DHCP server. It should be left to be disabled. However all information that I found in the Internet show to have that feature enabled.

My question is what is the benefit to use the Add DHCP option 82 feature in the function of preventing a rogue DHCP server?

Many Thanks.
 
User avatar
nichky
Forum Guru
Forum Guru
Posts: 1397
Joined: Tue Jun 23, 2015 2:35 pm

Re: DHCP Snooping and DHCP Option 82

Sat May 25, 2019 11:02 am

if you don't know like trainer how you expecting from us :)

Just a joke. I did discovery about that. i found:
viewtopic.php?t=120951

Also i got presentation regarding DHCP Server and Option 82.
As soon as i find that i send on this forum.
 
User avatar
ekarin
Trainer
Trainer
Topic Author
Posts: 34
Joined: Fri Jun 01, 2018 9:12 pm
Contact:

Re: DHCP Snooping and DHCP Option 82

Sat May 25, 2019 1:15 pm

Hi nicky,

Sorry. I thought you expect so high from the trainers. :-) They are also human like us. Just kidding :-) Some features are vendor-specific and proprietary, with little information. It would be better to get clear and correct answers in this forum, especially MikroTik supporting teams or other trainers (with MTCSE) or security-experienced people, or maybe from you if you have experienced on that. :-)

I have ever searched on the Internet and already found that information you shared before. The DHCP option 82 typically use in presence of DHCP relays to place the information about agent-remote-id and agent-circuit-id in that option. https://tools.ietf.org/html/rfc3046

In my case, DHCP relays are not included. I did a simple experiment by using only a DHCP server communicating with clients via a switch based on RouterOS. What I found is that the DHCP option 82 feature seems to be not necessary in preventing a rogue DHCP server in a network without DHCP relays because it works no matter the DHCP option 82 disabled or enabled. Anyone who experience this, please share your idea or knowledge.

Regards,
 
User avatar
nichky
Forum Guru
Forum Guru
Posts: 1397
Joined: Tue Jun 23, 2015 2:35 pm

Re: DHCP Snooping and DHCP Option 82

Tue Jun 18, 2019 2:22 pm

have a look , you can find something about DHCP Option 82
You do not have the required permissions to view the files attached to this post.
 
User avatar
ekarin
Trainer
Trainer
Topic Author
Posts: 34
Joined: Fri Jun 01, 2018 9:12 pm
Contact:

Re: DHCP Snooping and DHCP Option 82

Wed Nov 20, 2019 12:49 pm

I found that the information about DHCP Option 82 in the following MikroTik website is clear.
https://wiki.mikrotik.com/wiki/Manual:Interface/Bridge
 
bl00dy
just joined
Posts: 4
Joined: Fri Nov 04, 2016 8:00 pm

Re: DHCP Snooping and DHCP Option 82

Thu Mar 12, 2020 4:12 pm

have a look , you can find something about DHCP Option 82
Hello,

Not sure I find anything about option 82 in this PDF

Ed
 
RaviB
just joined
Posts: 3
Joined: Thu Dec 09, 2021 5:43 am

Re: DHCP Snooping and DHCP Option 82

Tue Feb 14, 2023 8:06 pm

if you enable dhcp snooping on your router it can detect and prevent rogue dhcp server.

dhcp option 86 is an extra feature. if a host supports and uses the option, it will be informed about which network dhcp server is legitmate that it should utilze.