Professional Documents
Culture Documents
F B
STP Manipulation Attack
Root Bridge
Priority = 8192
F F B
F
F
F F F
F B F F
Root
Bridge
F
F
F B
BPDU
Guard
Enabled
STP
Attacker BPDU
Switch(config)#
spanning-tree portfast bpduguard default
• Globally enables BPDU guard on all ports with PortFast
enabled
Root Guard
Root Bridge
Priority = 0
F F
MAC Address =
0000.0c45.1a5d
F F
Root
Guard
Enabled
F B
F
STP BPDU
Attacker Priority = 0
MAC Address = 0000.0c45.1234
Switch(config-if)#
spanning-tree guard root
• Enables root guard on a per-interface basis
Virtual LANs
• A campus network should be designed using small bandwidth and
small broadcast domains.
• a bandwidth domain is also called a collision domain.
• A broadcast domain is a set of devices that can all hear each other’s
broadcast frames. The campus access layer should use switches
and provide broadcast control, however. To accomplish this, virtual
LANs are necessary.
LAN Storm Attack
Broadcast Broadcast
Broadcast Broadcast
Broadcast Broadcast
▪ Segmentation
▪ Flexibility
▪ Security
802.1Q VLAN
10
Trunk
VLAN Server
20
0/1
0/2
0/3
MAC A
MAC F
Attacker 1
Trunk
(Native VLAN = 10)