Cisco 2975 - Catalyst LAN Base Switch Manual de usuario Pagina 10

  • Descarga
  • Añadir a mis manuales
  • Imprimir
  • Pagina
    / 29
  • Tabla de contenidos
  • MARCADORES
  • Valorado. / 5. Basado en revisión del cliente
Vista de pagina 9
10
© 2006 Cisco Systems, Inc. All rights reserved. Cisco ConfidentialPresentation_ID
19
Dynamic ARP Inspection
My GW Is
10.1.1.1
IP: 10.1.1.1
10.1.1.2
I’m Your
GW: 10.1.1.1
Not by My
Binding Table
Gratuitous ARP to Change End
Device MAC to ARP Tables
What It Does:
Maintains a binding table containing IP and MAC address
associations dynamically populated using DHCP Snooping
Benefit:
Ensures integrity of user and default gateway information such that
traffic cannot be captured
MAC: 0000.0000.0001
© 2006 Cisco Systems, Inc. All rights reserved. Cisco ConfidentialPresentation_ID
20
IP Spoofing Attack
“I’m assigned IP
address
10.2.2.15”
“I’m going to
steal address
10.2.2.15”
Discarding attacker’s packets with spoofed
source IP address by binding client IP
address, client MAC address, port, VLAN
number
Users change their assigned IP
address either due to:
Innocent reasons
A way to hide an attack by
bypassing ACLs, appearing to be on a
different subnet or launch
anonymous DoS attacks
Problem:
Problem:
Solution:
Solution:
“I’m assigned IP
address
10.2.2.15”
“I’m going to
steal address
10.2.2.15”
No, you’re not!
Vista de pagina 9
1 2 ... 5 6 7 8 9 10 11 12 13 14 15 ... 28 29

Comentarios a estos manuales

Sin comentarios