DHCP Fingerprint Forwarding Support (DHCP Local Server and DHCP Relay)

This topic describes how to enable DHCP fingerprinting forwarding to mirror client DHCP messages to fingerprinting servers for device identification and policy enforcement.

Overview

DHCP fingerprinting identifies devices on a network by analysing the DHCP messages sent by client devices when requesting an IP address. Fingerprinting servers use patterns in these messages—based on device type, operating system, and vendor—to examine the combination and ordering of DHCP options.

For DHCPv4, commonly observed options include Option 55 (Parameter Request List), Option 60 (Vendor Class Identifier), and Option 77 (User Class Identifier). These patterns together form a unique “fingerprint” that can be used to identify and classify devices. Similarly for DHCPv6, a different set of options are used. The specific options used for fingerprinting are determined by the fingerprinting server implementation and does not affect the behaviour of the Junos DHCP relay agent or local server.

A Junos OS device processes DHCP messages normally as a relay agent or a DHCP local server. When DHCP fingerprinting forwarding is enabled, it additionally mirrors validated client DHCP packets to configured fingerprinting servers.

For DHCPv4, fingerprinting typically uses messages such as DHCPDISCOVER and DHCPREQUEST. For DHCPv6, the corresponding message types include DHCPv6 SOLICIT and DHCPv6 REQUEST.

The DHCP fingerprint server passively analyses the mirrored DHCP messages to derive fingerprints (such as from option sets and ordering) for device identification or policy decisions, without participating in IP address assignment.

Benefits of DHCP Fingerprinting Packet Forwarding

  • Detect and block unauthorized devices.
  • Automatically classify devices (for example, phones, laptops, IoT) for inventory and reporting.
  • Assign devices to specific VLANs or subnets based on their type.
  • Apply device-specific network policies and configurations.
  • Maintain detailed logs for visibility and compliance.

How Packet Forwarding Works?

Figure 1 and Figure 2 shows DHCP fingerprint forwarding in Junos OS.
Figure 1: DHCP Fingerprint Packet Forwarding (DHCP Local Server) DHCP Fingerprint Packet Forwarding (DHCP Local Server)
Figure 2: DHCP Fingerprint Packet Forwarding (DHCP Relay Agent) DHCP Fingerprint Packet Forwarding (DHCP Relay Agent)
  • The DHCP client sends DHCP messages as part of the normal IP address allocation process (DHCPv4 or DHCPv6).
  • A Junos OS device, acting as DHCP relay agent or local DHCP server, receives these client messages and continues regular DHCP functions. When DHCP fingerprint packet forwarding is enabled, the device additionally creates stateless copies of the eligible DHCPv4/DHCPv6 packets and forwards the copies to configured fingerprint servers. The device performs this copy operation independently of the DHCP relay and DHCP local server state machines.
  • These packet copies are forwarded with minimal changes to preserve the original DHCP fingerprint (example: the device does not alter Option 82, and does not add DHCPv6 relay encapsulation to the copied packets); however, the giaddr field in DHCPv4 packets may be modified before forwarding to the fingerprint server.
  • The DHCP local server/DHCP relay agent device can send these packet copies to up to four DHCP fingerprint servers. Because the forwarding is stateless, the device does not create per-client fingerprint sessions and does not expect replies from the fingerprint servers.
  • Packet copies can be sent via specific logical systems and routing instances, allowing the fingerprinting servers to reside in a different routing instance than the subscriber access network or upstream DHCP servers, without requiring route leaking.
  • The DHCP fingerprint server receives the copied DHCP messages from the relay/local server.
  • It analyzes these messages to derive DHCP fingerprints (for example, based on option sets, option ordering, and other DHCP header/option characteristics).
  • The fingerprint server uses these fingerprints for purposes such as device identification, profiling, or policy decisions, without participating directly in the IP address assignment.

Configure DHCP Fingerprint Packet Forwarding

Configuring DHCP fingerprint forwarding includes:

  • Define multiple fingerprint server groups for DHCPv6 and DHCPv4.
  • Select one active fingerprint server group globally, and optionally override it per DHCP group.
  • Specify each server address with an optional logical system and routing instance context.
  • Resolve reachability and forward the fingerprint copy using the routing-instance (and optional logical-system) context bound to the server address, without leaking routes between routing domains.

Table 1 and Table 2 show configuration statements used for DHCP fingerprint forwarding.

Table 1: Commands to Configure DHCP Local Server Fingerprint Forwarding and Group Associations
Scope Action Configuration Statements

Global-level

Define a fingerprint server group (up to four IPv4 addresses).

DHCPv4

[edit]
user@host# set system services dhcp-local-server 
fingerprint-server-group name ipv4-address

DHCPv6

[edit]
user@host# set system services dhcp-local-server dhcpv6
fingerprint-server-group name ipv6-address
Activate the fingerprint server group.

DHCPv4

user@host# set system services dhcp-local-server 
active-fingerprint-server-group name

DHCPv6

user@host# set system services dhcp-local-server dhcpv6
active-fingerprint-server-group name
(Optional) Set a logical system context for fingerprint server communication.

DHCPv4

user@host# set system services dhcp-local-server fingerprint-server-group name ipv4-address
logical-system default|name

DHCPv6

user@host# set system services dhcp-local-server dhcpv6
fingerprint-server-group name ipv6-address logical-system default|name
(Optional) Set a routing instance context for fingerprint server communication.

DHCPv4

user@host# set system services dhcp-local-server 
fingerprint-server-group name ipv4-address routing-instance default|name

DHCPv6

user@host# set system services dhcp-local-server dhcpv6 fingerprint-server-group name ipv6-address routing-instance default|name
Group-specific Associate a DHCP group with an active fingerprint server group.

DHCPv4

user@host# set system services dhcp-local-server group name 
 active-fingerprint-server-group name

DHCPv6

user@host# set system services dhcp-local-server dhcpv6 group  name 
 active-fingerprint-server-group name
Multi-tenant (within a logical system and routing instance) Define a tenant-scoped fingerprint server group.

DHCPv4

user@host# set logical-systems name 
routing-instances name system services dhcp-local-server 
fingerprint-server-group name ipv4-address

DHCPv6

user@host# set logical-systems name 
routing-instances name system services dhcp-local-server dhcpv6
fingerprint-server-group name ipv6-address
Activate the tenant-scoped fingerprint server group.

DHCPv4

user@host# set logical-systems name routing-instances name 
system services dhcp-local-server active-fingerprint-server-group name

DHCPv6

user@host# set logical-systems name routing-instances name 
system services dhcp-local-server dhcpv6  
active-fingerprint-server-group name
Create cross-context reference to a logical system for a fingerprint services defined in the default or another logical system.

DHCPv4

user@host# set logical-systems name routing-instances name 
system services dhcp-local-server fingerprint-server-group name ipv4-address logical-system default|name

DHCPv6

user@host# set logical-systems name routing-instances name 
system services dhcp-local-server dhcpv6 fingerprint-server-group name ipv6-address logical-system default|name
Create cross-context reference to a routing instance for fingerprint services defined in the default or another routing instance.

DHCPv4

user@host# set logical-systems name routing-instances name
system services dhcp-local-server fingerprint-server-group name ipv4-address routing-instance default|name

DHCPv6

user@host# set logical-systems name routing-instances name
system services dhcp-local-server dhcpv6 fingerprint-server-group name ipv6-address routing-instance default|name
Multi-tenant, group-specific Associate a tenant DHCP group with an active fingerprint server group.

DHCPv4

user@host# set logical-systems name routing-instances name 
system services dhcp-local-server group name active-fingerprint-server-group name

DHCPv6

user@host# set logical-systems name routing-instances name 
system services dhcp-local-server dhcpv6 group name active-fingerprint-server-group name
Table 2: Commands to Configure DHCP Relay Agent Fingerprint Forwarding and Group Associations Sssociations
Scope: Action Configuration Statements

Global

Create a fingerprint server group and associate it with a server IP address.

DHCPv4

user@host# set forwarding-options dhcp-relay 
fingerprint-server-group name ipv4-address

DHCPv6

user@host# set forwarding-options dhcp-relay dhcpv6
fingerprint-server-group name IPv6-address
Activate the fingerprint server group.

DHCPv4

user@host# set forwarding-options dhcp-relay 
active-fingerprint-server-group name

DHCPv6

user@host# set forwarding-options dhcp-relay dhcpv6
active-fingerprint-server-group name
(Optional) Set a logical system context for fingerprint server communication.

DHCPv4

user@host# set forwarding-options dhcp-relay 
fingerprint-server-group name ipv4-address logical-system default|name

DHCPv6

user@host# set forwarding-options dhcp-relay dhcpv6
fingerprint-server-group name ipv6-address logical-system default|name
(Optional) Set a routing instance context for fingerprint server communication.

DHCPv4

user@host# set forwarding-options dhcp-relay 
fingerprint-server-group name ipv4-address routing-instance default|name

DHCPv6

user@host# set forwarding-options dhcp-relay dhcpv6
fingerprint-server-group name ipv6-address routing-instance default|name
Group-specific Associate a DHCP group with an active fingerprint server group.

DHCPv4

user@host# set forwarding-options dhcp-relay group name active-fingerprint-server-group name

DHCPv6

user@host# set forwarding-options dhcp-relay group dhcpv6 name 
fingerprint-server active-fingerprint-server-group name
Multi-tenant (within a logical system and routing instance) Define a tenant-scoped fingerprint server group.

DHCPv4

user@host# set logical-systems name 
routing-instances name forwarding-options dhcp-relay 
fingerprint-server-group name ipv4-address

DHCPv6

user@host# set logical-systems name 
routing-instances name forwarding-options dhcp-relay dhcpv6
fingerprint-server-group name ipv6-address
Activate the tenant-scoped fingerprint server group.

DHCPv4

user@host# set logical-systems name routing-instances name 
forwarding-options dhcp-relay active-fingerprint-server-group name

DHCPv6

user@host# set logical-systems name routing-instances name 
forwarding-options dhcp-relay dhcpv6 active-fingerprint-server-group name
Create cross-context reference to a logical system for a fingerprint services defined in the default or another logical system.

DHCPv4

user@host# set logical-systems name routing-instances name 
forwarding-options dhcp-relay fingerprint-server-group name ipv4-address logical-system default|name

DHCPv6

user@host# set logical-systems name routing-instances name 
forwarding-options dhcp-relay dhcpv6 fingerprint-server-group name ipv6-address logical-system default|name
Note: Replace placeholders with your values. Use default to reference the default context, or specify logical-system-name and routing-instance-name as needed.

Configuration Sample

Following samples show configuration of fingerprint servers. This configuration tells the Junos OS device (operating as a DHCP local server), where to send DHCP fingerprint information for DHCP clients.

DHCPv4 Sample Configuration

In the above sample:

  • MY‑V4‑FP‑SGRP‑1 contains one fingerprint server (172.16.0.2). This server uses the current logical system and current routing instance).
  • MY-V4-FP-SGRP-2 contains two fingerprint servers, each with its own context. That is, to reach 172.16.0.3, the device uses the routing-instance MY-LS and to reach 172.16.0.4, the device first goes into logical-system MY-LS, then uses routing-instance MY-RI-2 inside that LS.
  • DFLT-LS-V4-FP-SERVER-GROUP-1 is globally active fingerprint server group. if notrhing overrides it, DHCPv6 fingerprint data will go to 172.16.0.2.
  • You have two DHCP client groups defined:
    • DFLT-LS-V4-CLIENT-GROUP-1—This group does not override the fingerprint server group. This group uses the global active-fingerprint-server-group DFLT-LS-V4-FP-SERVER-GROUP-1.

    • DFLT-LS-V4-CLIENT-GROUP-2—This group overrides the global setting and uses DFLT-LS-V4-FP-SERVER-GROUP-2 as the active fingerprint server group.

Similarly the following configuration snippets show DHCPv6 local server, DHCPv4 and DHCPv6 Relay Agent samples.

DHCPv6 Sample Configuration

This configuration sets up multiple DHCPv6 fingerprint server groups, with a global active group and an override at the client-group level to direct different clients to specific fingerprint servers.

DHCP Relay Agent Sample Configuration

This configuration sets up multiple DHCPv4 and DHCPv6 relay fingerprint server groups, with a global active group and an override at the client-group level to direct different clients to specific fingerprint servers across multiple logical-system and routing-instance contexts.

Verify Configuration

To verify forwarding, use per-routing-instance counters that track packets sent to fingerprint servers regardless of whether later DHCP processing succeeds.

For DHCPv4, use the following command:

For DHCPv6, use the following command:

Use the following commands to clear DHCP fingerprint forwarding statistics:

  • clear dhcp fingerprint statistics
  • clear dhcpv6 fingerprint statistics