Check-Mac-Address
These scenarios show how the
check-mac-address feature works for the DHCP server
Test Check MAC Address
Description
The check-mac-address option filters packets if there are differences between the MAC address found at the ethernet header and the MAC address found in the DHCP packet.
To check this option, you should send packets with these differences and enable this option to see if warnings appear in your logs.
Also, this test checks how the server behaves under normal conditions.
Scenario
Step 1: Set the following configuration in DUT0 :
set interfaces ethernet eth0 address 10.0.0.1/24 set service dhcp-server shared-network dhcp subnet 10.0.0.0/24 start 10.0.0.5 stop 10.0.0.5 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
Step 2: Run the command system journal show | tail on DUT0 and check whether the output contains the following tokens:
DHCPDISCOVER from 10:00:00:00:00:02 via eth0Show output
Sep 16 22:54:12.435535 osdx dhcpd[423688]: Wrote 0 leases to leases file. Sep 16 22:54:12.484629 osdx dhcpd[423688]: Server starting service. Sep 16 22:54:12.625426 osdx cfgd[1899]: [423249]Completed change to active configuration Sep 16 22:54:12.625947 osdx OSDxCLI[423249]: User 'admin' committed the configuration. Sep 16 22:54:12.646515 osdx OSDxCLI[423249]: User 'admin' left the configuration menu. Sep 16 22:54:12.773474 osdx OSDxCLI[423249]: User 'admin' executed a new command: 'system journal show | tail'. Sep 16 22:54:13.430073 osdx dhcpd[423688]: DHCPDISCOVER from 10:00:00:00:00:02 via eth0 Sep 16 22:54:14.430884 osdx dhcpd[423688]: DHCPOFFER on 10.0.0.5 to 10:00:00:00:00:02 via eth0 Sep 16 22:54:14.482009 osdx dhcpd[423688]: DHCPDISCOVER from 10:00:00:00:00:02 via eth0 Sep 16 22:54:14.482040 osdx dhcpd[423688]: DHCPOFFER on 10.0.0.5 to 10:00:00:00:00:02 via eth0
Step 3: Modify the following configuration lines in DUT0 :
set service dhcp-server check-mac-address
Step 4: Run the command system journal clear on DUT0.
Step 5: Run the command system journal show | tail on DUT0 and check whether the output does not contain the following tokens:
DHCPDISCOVER from 10:00:00:00:00:02 via eth0Show output
Sep 16 22:54:15.501592 osdx systemd-journald[303514]: Runtime Journal (/run/log/journal/7ab9d0c6c88d486ab30f6cca192546c5) is 2.5M, max 13.8M, 11.2M free. Sep 16 22:54:15.504497 osdx systemd-journald[303514]: Received client request to rotate journal, rotating. Sep 16 22:54:15.504576 osdx systemd-journald[303514]: Vacuuming done, freed 0B of archived journals from /run/log/journal/7ab9d0c6c88d486ab30f6cca192546c5. Sep 16 22:54:15.515327 osdx OSDxCLI[423249]: User 'admin' executed a new command: 'system journal clear'. Sep 16 22:54:15.546092 osdx dhcpd[423761]: MAC received in DHCP packet (10:00:00:00:00:02) is different than source MAC in ethernet header (10:00:00:00:00:01)
Step 6: Run the command system journal show | tail on DUT0 and check whether the output contains the following tokens:
MAC received in DHCP packet (10:00:00:00:00:02) is different than source MAC in ethernet header (10:00:00:00:00:01)Show output
Sep 16 22:54:15.501592 osdx systemd-journald[303514]: Runtime Journal (/run/log/journal/7ab9d0c6c88d486ab30f6cca192546c5) is 2.5M, max 13.8M, 11.2M free. Sep 16 22:54:15.504497 osdx systemd-journald[303514]: Received client request to rotate journal, rotating. Sep 16 22:54:15.504576 osdx systemd-journald[303514]: Vacuuming done, freed 0B of archived journals from /run/log/journal/7ab9d0c6c88d486ab30f6cca192546c5. Sep 16 22:54:15.515327 osdx OSDxCLI[423249]: User 'admin' executed a new command: 'system journal clear'. Sep 16 22:54:15.546092 osdx dhcpd[423761]: MAC received in DHCP packet (10:00:00:00:00:02) is different than source MAC in ethernet header (10:00:00:00:00:01) Sep 16 22:54:15.597314 osdx OSDxCLI[423249]: User 'admin' executed a new command: 'system journal show | tail'.
Step 7: Set the following configuration in DUT1 :
set interfaces ethernet eth0 mac '10:00:00:00:00:05' set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
Step 8: Modify the following configuration lines in DUT1 :
set interfaces ethernet eth0 address dhcp
Step 9: Run the command interfaces ethernet eth0 show on DUT1 and check whether the output contains the following tokens:
10.0.0.5Show output
----------------------------------------------------------------- Name IP Address Admin Oper Vrf Description ----------------------------------------------------------------- eth0 10.0.0.5/24 up up fe80::dcad:beff:feef:6c10/64
Step 10: Run the command service dhcp-server show leases main | grep 10.0.0.5 on DUT0 and check whether the output contains the following tokens:
10:00:00:00:00:05Show output
10.0.0.5 10:00:00:00:00:05 2026/09/16 22:54:18 2026/09/17 10:54:18 2026/09/16 22:54:18
Test Check MAC Address VRF
Description
This scenario configures a DHCP server with VRF instead of regular interfaces and checks the check-mac-address option.
To check this option, you will need to send packets with differences in the Source MAC for the link layer and the client MAC from the application layer.
Scenario
Step 1: Set the following configuration in DUT0 :
set interfaces ethernet eth0 address 10.0.0.1/24 set interfaces ethernet eth0 vrf VRF0 set service dhcp-server shared-network dhcp local-vrf VRF0 set service dhcp-server shared-network dhcp subnet 10.0.0.0/24 start 10.0.0.5 stop 10.0.0.6 set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0' set system vrf VRF0
Step 2: Run the command system journal show | tail on DUT0 and check whether the output contains the following tokens:
DHCPDISCOVER from 10:00:00:00:00:02 via eth0Show output
Sep 16 22:54:27.921390 osdx dhcpd[424193]: Wrote 0 leases to leases file. Sep 16 22:54:27.961898 osdx dhcpd[424193]: Server starting service. Sep 16 22:54:28.115066 osdx cfgd[1899]: [423249]Completed change to active configuration Sep 16 22:54:28.115809 osdx OSDxCLI[423249]: User 'admin' committed the configuration. Sep 16 22:54:28.137431 osdx OSDxCLI[423249]: User 'admin' left the configuration menu. Sep 16 22:54:28.286315 osdx OSDxCLI[423249]: User 'admin' executed a new command: 'system journal show | tail'. Sep 16 22:54:28.566947 osdx dhcpd[424193]: DHCPDISCOVER from 10:00:00:00:00:02 via eth0 Sep 16 22:54:29.567117 osdx dhcpd[424193]: DHCPOFFER on 10.0.0.5 to 10:00:00:00:00:02 via eth0 Sep 16 22:54:29.651012 osdx dhcpd[424193]: DHCPDISCOVER from 10:00:00:00:00:02 via eth0 Sep 16 22:54:29.651057 osdx dhcpd[424193]: DHCPOFFER on 10.0.0.5 to 10:00:00:00:00:02 via eth0
Step 3: Modify the following configuration lines in DUT0 :
set service dhcp-server check-mac-address
Step 4: Run the command system journal clear on DUT0.
Step 5: Run the command system journal show | tail on DUT0 and check whether the output does not contain the following tokens:
DHCPDISCOVER from 10:00:00:00:00:02 via eth0Show output
Sep 16 22:54:31.210119 osdx systemd-journald[303514]: Runtime Journal (/run/log/journal/7ab9d0c6c88d486ab30f6cca192546c5) is 1.8M, max 13.8M, 11.9M free. Sep 16 22:54:31.213748 osdx systemd-journald[303514]: Received client request to rotate journal, rotating. Sep 16 22:54:31.213871 osdx systemd-journald[303514]: Vacuuming done, freed 0B of archived journals from /run/log/journal/7ab9d0c6c88d486ab30f6cca192546c5. Sep 16 22:54:31.223367 osdx OSDxCLI[423249]: User 'admin' executed a new command: 'system journal clear'.
Step 6: Run the command system journal show | tail on DUT0 and check whether the output contains the following tokens:
MAC received in DHCP packet (10:00:00:00:00:02) is different than source MAC in ethernet header (10:00:00:00:00:01)Show output
Sep 16 22:54:31.210119 osdx systemd-journald[303514]: Runtime Journal (/run/log/journal/7ab9d0c6c88d486ab30f6cca192546c5) is 1.8M, max 13.8M, 11.9M free. Sep 16 22:54:31.213748 osdx systemd-journald[303514]: Received client request to rotate journal, rotating. Sep 16 22:54:31.213871 osdx systemd-journald[303514]: Vacuuming done, freed 0B of archived journals from /run/log/journal/7ab9d0c6c88d486ab30f6cca192546c5. Sep 16 22:54:31.223367 osdx OSDxCLI[423249]: User 'admin' executed a new command: 'system journal clear'. Sep 16 22:54:31.335647 osdx OSDxCLI[423249]: User 'admin' executed a new command: 'system journal show | tail'. Sep 16 22:54:31.466966 osdx OSDxCLI[423249]: User 'admin' executed a new command: 'system journal show | tail'. Sep 16 22:54:31.798621 osdx dhcpd[424266]: MAC received in DHCP packet (10:00:00:00:00:02) is different than source MAC in ethernet header (10:00:00:00:00:01) Sep 16 22:54:32.842808 osdx dhcpd[424266]: MAC received in DHCP packet (10:00:00:00:00:02) is different than source MAC in ethernet header (10:00:00:00:00:01)
Step 7: Set the following configuration in DUT1 :
set interfaces ethernet eth0 mac '10:00:00:00:00:05' set system login user admin authentication encrypted-password '$6$GSjsCj8gHLv$/VcqU6FLi6CT2Oxn0MJQ2C2tqnRDrYKNF8HIYWJp68nvXvPdFccDsT04.WtigUONbKYrgKg8d6rEs8PjljMkH0'
Step 8: Modify the following configuration lines in DUT1 :
set interfaces ethernet eth0 address dhcp
Step 9: Run the command interfaces ethernet eth0 show on DUT1 and check whether the output contains the following tokens:
10.0.0.5Show output
----------------------------------------------------------------- Name IP Address Admin Oper Vrf Description ----------------------------------------------------------------- eth0 10.0.0.5/24 up up fe80::dcad:beff:feef:6c10/64
Step 10: Run the command service dhcp-server show leases VRF0 | grep 10.0.0.5 on DUT0 and check whether the output contains the following tokens:
10:00:00:00:00:05Show output
10.0.0.5 10:00:00:00:00:05 2026/09/16 22:54:36 2026/09/17 10:54:36 2026/09/16 22:54:36