SV-80561r1_rule
V-66071
SRG-NET-000362-L2S-000025
HFFS-L2-000014
CAT II
10
Configure the HP FlexFabric Switch to have DHCP snooping for all user VLANs to validate DHCP messages from untrusted sources as well as rate-limit DHCP traffic.
[HP]dhcp snooping enable
[HP-GigabitEthernet1/0/1]dhcp snooping rate-limit
Review the HP FlexFabric Switch configuration and verify that DHCP snooping is enabled on a per-VLAN basis.
If the HP FlexFabric Switch does not have DHCP snooping enabled for all user VLANs to validate DHCP messages from untrusted sources as well as rate-limit DHCP traffic, this is a finding.
Note: Enabling DHCP snooping on a range of VLANs is permissible.
Sample output:
[HP]dhcp snooping enable
[HP-GigabitEthernet1/0/1]dhcp snooping rate-limit
V-66071
False
HFFS-L2-000014
Review the HP FlexFabric Switch configuration and verify that DHCP snooping is enabled on a per-VLAN basis.
If the HP FlexFabric Switch does not have DHCP snooping enabled for all user VLANs to validate DHCP messages from untrusted sources as well as rate-limit DHCP traffic, this is a finding.
Note: Enabling DHCP snooping on a range of VLANs is permissible.
Sample output:
[HP]dhcp snooping enable
[HP-GigabitEthernet1/0/1]dhcp snooping rate-limit
M
2977