Cisco ME-3400G-12CS-A-RF - Ethernet Access Switch Manual de usuario Pagina 110

  • Descarga
  • Añadir a mis manuales
  • Imprimir
  • Pagina
    / 137
  • Tabla de contenidos
  • MARCADORES
  • Valorado. / 5. Basado en revisión del cliente
Vista de pagina 109
© 2009 Cisco Systems, Inc. All rights reserved.
111
Cisco PublicBRKBBA-2006
Risk :
• A rogue user spoof a DHCP server and send fake DNS, IP, Default. Gateway
DHCP request
DHCP request
DHCP Ack
DHCP Ack
X
X
Rogue Server
Trusted Port
Valid
DHCP
Server
Untrustred Port for
DHCP
Untrusted Ports
Prevent denial of service (DoS) attacks based on DHCP protocol
Malicious—user pretends to be the Network DHCP Server
Misconfiguration—user configures router (DHCP server) incorrectly
How it works:
The access switch only forwards DHCP requests from access ports (untrusted
ports); All other types of DHCP traffic from access ports is dropped
If the server is not local to the Catalyst Switch, trust the uplink port
DoS attack can be prevented by rate limiting the DHCP packets on access ports
DHCP Snooping
Vista de pagina 109
1 2 ... 105 106 107 108 109 110 111 112 113 114 115 ... 136 137

Comentarios a estos manuales

Sin comentarios