Community discussions

MikroTik App
 
Garrison1701
just joined
Topic Author
Posts: 9
Joined: Tue Jun 19, 2018 5:10 pm

Combating Rogue DHCP Servers

Wed Aug 22, 2018 6:58 pm

Hey Everyone,

I've recently been running into trouble with rogue DHCP servers plugged into customer ports at several apartment buildings that we service. After some Google searching, I found the CRS switch manual here that details how to deal with this particularly the protocol level isolation mentioned here: https://wiki.mikrotik.com/wiki/Manual: ... solation. . I would like to implement this across our network, but it appears to be only for CRS. Most of our apartment buildings use powerboxes (RB750s) for customer edge connections. Is there another solution that I can implement that would be supported by an RB750?

Thanks!
 
PashaT
just joined
Posts: 19
Joined: Sat Feb 01, 2014 1:10 am
Location: Zhytomyr, Ukraine

WIP

Wed Aug 29, 2018 12:08 am

From 6.43rc release notes:
*) bridge - added support for DHCP Snooping (CLI only);
 
User avatar
Cha0s
Forum Guru
Forum Guru
Posts: 1142
Joined: Tue Oct 11, 2005 4:53 pm

Re: Combating Rogue DHCP Servers

Wed Aug 29, 2018 2:23 am

There's also an "Alerts" section in DHCP Server which can monitor for rogue DHCP servers and alert you.
https://wiki.mikrotik.com/wiki/Manual:I ... ver#Alerts

It also allows for "On Alert" scripting which could be used to disable the offending ports or apply firewall rules.
There's a relevant post on blocking DHCP here (I haven't tested it myself): viewtopic.php?t=101249
 
PashaT
just joined
Posts: 19
Joined: Sat Feb 01, 2014 1:10 am
Location: Zhytomyr, Ukraine

Re: Combating Rogue DHCP Servers

Wed Aug 29, 2018 1:13 pm

Also you need to know that RB750 will turn off Bridge Hardware Offloading with Bridge DHCP Snooping enabled for ROS 6.41+.

Bridge filtering will drop performance too.

Who is online

Users browsing this forum: GoogleOther [Bot] and 76 guests