Re: iptables and dhcp

From: W Cardwell (wrong_at_email.address)
Date: 09/16/03


Date: Tue, 16 Sep 2003 13:59:45 GMT


>
> They are not on the same physical segment: my firewall sits in between.

Since you're using a bridging firewall they are on the same IP broadcast
domain. If you use a routing firewall, DHCP broadcasts won't pass through.

>
> >> I've tried blocking ports 67 and 68 with iptables, and it still gets
> >> passed through and serviced. I've tried blocking everything in both
> >> directions and it still gets passed through.
> >>
> >> Any ideas?
> >

Iptables can't filter DHCP packets for some reason that I've never seen
adequately explained. If you can't switch to a routing firewall, you might
have to resort to MAC address matching at the DHCP server to prevent it
assigning addresses to machines beyond the firewall.



Relevant Pages

  • Re: HELP REQUIRED - Strange Hacking Attempt!!!!
    ... > The initial DHCP request is broadcast from 0.0.0.0:68 to ... and this is such a normal occurrence that no firewall ... > If the DHCP request has the broadcast flag set, ...
    (comp.security.firewalls)
  • SunScreen and Broadcasts
    ... firewall and have had a lot of frustration trying to get help ... through Sun's support. ... interface on the backup network isn't even connected. ... traffic to the broadcast address of the internal ...
    (Focus-SUN)
  • TCP Connections to a Broadcast Address on BSD-Based Systems
    ... BSD-based TCP/IP code has a bug with respect to creating TCP ... TCP implementation works correctly and do not block broadcast ... firewall host or gateway, the potential for exploitation is probably ...
    (Bugtraq)
  • Re: TCP - UDP Ports used in file sharing & associated anomolies
    ... I would think a router would be a much ... > The firewall isn't for security reasons... ... > It segregates a hardware lab from the production network. ... this is b/c the hardware being developed emits a broadcast UDP packet every ...
    (microsoft.public.windows.server.networking)
  • Re: iptables DNAT --to-destination problem
    ... > No sane router will forward a general broadcast. ... >> The generated package can not be logged by the Firewall, ... After that includes the firewall doesnt logg FORWARD packages too :-( ... The computer B can't sniff the Broadcast message on eth1, ...
    (comp.os.linux.security)