Security Topics
Security Topics
( STP )
Spaning tree protocol
network Design
Redundant topology
switch
Broadcast storm
STP devices
switch STP
frames Forward Root
logical switches
STP ATTACK
priority Root
priority STP ATTACK
BPDU
BPDU Root
Root ATTACKER switches
ATTACK
Portfast ACCESS
BPDU Guard
BPDU
Root guard
config mode portfast configuration
interface
(config)int g0/1
(config-if)switchport mode access
(config-if)spaning-tree portfast
interface
(config)int g1/1
(config-if) spaning-tree guard root
DHCP Starvation ATTACK
DHCP Spoofing ATTACK
IP DHCP
DNS Gateway Subnet mask
DHCP Client
DHCP Discover Client
offer DHCP
request Client
Acknowledge
DHCP Server
MAC IP ATTACK
Pool DHCP
IP IP Attacker
Gateway APIPA IP
DNS
Dos ATTACK
DHCP
Configuration
DHCP Spoofing ATTACK ATTACK
ATTACKS
DHCP DHCP Snooping
DHCP
untrusted Trusted DHCP Server
Snooping
untrusted vlan 1
DHCP
trusted
Command
F0/1 DHCP
(config)int f0/1
(config-if)ip dhcp snooping trust
untrusted
Discover Interface
error DHCP Server
disable state
command
Discover
IP Source Guard
DHCP
Security
DHCP Snooping
Configuration DHCP DHCP
Manual user
Pool Script
Pool offer DHCP
ATTACK-user
BAD IP DHCP
IP address
Service DHCP
IP SOURCE GUARD
interface port-security
Action
: Configuration
interfaces
command
int f0/1
ip verify source
DHCP
IP source Guard snooping
ARP Poison ARP Spoofing
MAC ARP
IP
MAC address IP
ARP Cash
MAC Address
ARP Request
IP MAC Address
:
IP
IP
Broadcast
MAC Address
ARP Cash
Destination
MAC Users
Destination Address
Snooping Table
IP
ARP
Configuration
(config)ip arp inspection vlan1
Vlan1
DHCP
(config)int f0/3
(config-if)ip arp inspection trust
Users
(config)int rang f0/4-24
Command