L28
DHCP, rogue DHCP, starvation and snooping
Cram this first — memory hook
Discover, Offer, Request, Acknowledge finds your address. Landlord 67 gives tenant 68 a home. Rogue = wrong landlord; starvation = no homes left.
Exam trap
An address was assigned does not mean the settings came from an authorized server. Two offers may also be legitimate redundancy, so verify the design.
The slide facts
Module 9 page 36 explicitly contrasts rogue Dynamic Host Configuration Protocol with starvation. It recommends trusted paths, port security, rate limiting and watching unexpected replies.
If you have time — extra
Dynamic Host Configuration Protocol () provides address settings such as Internet Protocol address, subnet mask, default gateway and Domain Name System () server. For normal IPv4 discovery, remember Discover, Offer, Request, Acknowledge (). Servers commonly use User Datagram Protocol () 67 and clients 68. A rogue server can offer plausible-looking but harmful settings, sending traffic toward an attacker-controlled gateway or resolver. starvation consumes the pool by requesting many leases, leaving legitimate clients without addresses. A rogue server can also be an accidental misconfiguration; rogue does not prove malicious intent. snooping marks appropriate server-facing paths as trusted, blocks inappropriate server messages on untrusted access paths, and builds bindings useful to other controls. Trust is a topology decision: an uplink may legitimately lead to the server. Do not blindly trust every port or make all uplinks untrusted without understanding the network.
Walkthrough
The client discovers servers, receives offers, requests a selected offer and receives an acknowledgment. Check that the resulting lease, gateway and settings are expected. Compare offers and snooping logs if settings change unexpectedly.