Cisco CCNA (200-301)Security FundamentalsHard

A switch is under a DoS attack in which an attacker on an untrusted access port floods the network with DHCP DISCOVER messages, exhausting the DHCP server's lease pool. DHCP snooping is already enabled. Which additional configuration should the administrator apply to mitigate this specific attack while still allowing normal client DHCP requests?

  1. Aip dhcp snooping limit rate <value> on untrusted ports
  2. Bip dhcp snooping trust on the attacker's port
  3. Cip arp inspection validate src-mac
  4. Dip dhcp snooping verify mac-address on trusted ports
Show answer & explanation

Correct answer: A. ip dhcp snooping limit rate <value> on untrusted ports

The 'ip dhcp snooping limit rate' command caps the number of DHCP messages per second accepted on an untrusted interface, preventing an attacker from flooding the switch with DHCP DISCOVER packets while still allowing normal client traffic through at a reasonable rate.

Why the other options are wrong

  • B. Trusting the attacker's port would defeat the purpose of DHCP snooping and allow rogue server responses too.
  • C. This is a DAI validation option, not related to limiting DHCP DISCOVER floods.
  • D. Trusted ports are typically uplinks to the DHCP server, and verify mac-address is a DHCP snooping option for source MAC checking, not rate limiting.

DHCP Snooping Rate Limiting

The 'ip dhcp snooping limit rate' command restricts the number of DHCP packets per second on untrusted ports, mitigating DHCP flooding/DoS attacks.

  • Applied per interface, typically on untrusted access ports
  • Exceeding the rate causes the port to be error-disabled (if configured)
  • Complements trust configuration to fully secure DHCP

Memory trick: Rate-limit the flood before it drowns the DHCP pool.

More Security Fundamentals questions