Defense Against DHCP Flood Attacks
Mechanism
On a DHCP network, if an attacker sends a large number of DHCP messages to the device within a short time, device performance may deteriorate and the device may fail to work properly. This attack is called a DHCP flood attack.
Solution
To prevent DHCP flood attacks, enable DHCP snooping and enable the device to check the rate of sending DHCP messages to the processing unit. The device then sends only DHCP messages within a specified rate to the processing unit and discards those that exceed the rate.