Download as pdf or txt
Download as pdf or txt
You are on page 1of 3

2020

LAN Security for


CCNP SCOR Students
By
Eng. Abeer Hosni
LAN Security Attacks

1- CDP attack
Mitigation: Disable CDP globally or per interface level.

2- MAC spoofing and MAC (CAM) table flooding:


- Mitigation: Port security.

3- VLAN Hopping:
 Switch spoofing.
- Mitigation: Disable DTP negotiation.
 Double tagging.
- Mitigation: Tag the native VLAN.
- Mitigation: Don’t use the native VLAN.

4- DHCP Spoofing (DHCP Starvation / Rogue DHCP Server):


- Mitigation: DHCP snooping.

5- ARP Spoofing:
- Mitigation: DAI.

6- IP Spoofing:
Mitigation:
- Access Control List.
- IP source guard.

LAN Security Features


- Protected Ports.
- Private VLANs.
- Storm Control.
- Port Blocking.
- Control Plane rate-limiting.
STP Optimization
STP Convergence Optimization:
> PortFast
> UplinkFast
> BackboneFast

STP Filters:
> BPDU Filter
> BPDU Guard
> Root Guard

STP Loop Prevention:


> Loop Guard
> UDLD

Best Wishes
Abeer :)

You might also like