You are on page 1of 27

Advanced Switching Security

SPAN Port (Local Monitor Session)

switch(config)#monitor session 1 source interface fastethernet 0/1


switch(config)#monitor session 1 destination interface fastethernet 0/3
Authentication, Authorization,
Accounting
AAA
AAA
AAA
AAA
• Check the lab for configuration
1. Add the switch to Tacacs server
2. Add the user credentials on Tacacs server
3. Enable AAA on switch
4. Configure AAA configuration list on switch
5. Control telnet access using AAA
6. Test telnet between PC and Switch
AAA
• Configurations:
– aaa new-model
– aaa authentication login telnet group tacacs+ local
– Username cisco secret cisco
– Line vty 0 4
– Login authentication telnet
2- 802.1x authentication
802.1x authentication
802.1x authentication
802.1x authentication
802.1x authentication
3- DHCP Snooping
DHCP Snooping
DHCP Snooping
DHCP Snooping
DHCP Snooping & IP source Guard
4- Switch Stacking and Chassis
aggregation
Switches aggregation technologies
• All switches aggregation technologies are made to:
– overcome the limitation of spanning tree protocol.
– Increase speed of uplinks and downlinks connections.
• There are many technologies for chassis aggregations :
Technology name Switch model concept
Cisco Felxstack and 2960-S, 2960-X, and 2960- One control plane, one data
Flexstack plus XR plane (one complete virtual
switch)
Cisco Stackwise-480 3750-X, 3650, One control plane, one data
3850 (with stack power plane (one complete virtual
option) switch)
Cisco Virtual Switching 4500E, 4500-X, 6500, 6800 One control, two Data
System planes
Cisco VPC N56k,N7k and N77k Two control, two data
planes
Cisco Felxstack
Before Stacking
Cisco Felxstack
After Stacking
Cisco Felxstack
Cisco VSS
Cisco VSS
VSS + Stacking Benefits

You might also like