OS-5195

DHCP spoofing protection should allow permitting all Client Identifiers

Status:
Resolved
Resolution:
Fixed
Created:
2016-02-29T20:29:04.000-0500
Updated:
2018-06-08T14:49:54.657-0400

Description

There should be a link property on VNICs that allows permitting all DHCP Client Identifiers, since there's no way to reasonably track them, and for people setting up KVM instances, there's no way for them to reasonably know ahead of time what Client Identifier will be used during network setup during installation. This allow-all-dhcp-cids property will allow us to make it so that, unless someone has specified which CIDs are permitted, we can allow all through.

Comments (2)

Former user commented on 2018-06-07T20:00:17.270-0400:

To test these changes, I verified that:

Jira Bot commented on 2018-06-08T14:47:50.718-0400:

illumos-joyent commit c6b0ac12851403af18c06800770e65c0314956fb (branch master, by Cody Peter Mello)

OS-5195#icft=OS-5195 DHCP spoofing protection should allow permitting all Client Identifiers
Reviewed by: Robert Mustacchi <rm@joyent.com>
Approved by: Dan McDonald <danmcd@joyent.com>