BCMSN

Enterprise Composite Network Model

More Nested Compositte Network

The newer Cisco model the Enterprise Composite Model is significantly more complex and attempts to address the major shortcoming of the Hierarchical Design Model by expanding the older version and making specific recommendations about how and where certain network functions should be implemented. This model is based on the principles described in the Cisco Architecture for Voice, Video, and Integrated Data (AVVID). The Enterprise Composite Model is broken up into three large sections Enterprise...

Hot Standby Router Protocol HSRP

HSRP is a Cisco proprietary protocol. With HSRP, two or more devices support a virtual router with a fictitious MAC address and unique IP address. Hosts use this IP address as their default gateway, and the MAC address for the Layer 2 header. The virtual router's MAC address is 0000.0c07.ACxx, where xx is the HSRP group. Multiple groups (virtual routers) are allowed. The Active router forwards traffic. The Standby is backup. The standby monitors periodic hellos (multicast to 224.0.0.2, UDP port...

MAC Address Flooding

In a MAC address flooding attack, the attacker fills the switch's Content Addressable Memory (CAM) table with invalid MAC addresses. After the table is full, all traffic with an address not in the table is flooded out all interfaces. This has two bad effects more traffic on the LAN and more work for the switch. Additionally, the intruder's traffic is also flooded, so they have access to more ports than they would normally have. After the attack stops, CAM entries age out and life returns to...

Cisco Wireless Network Components

This section is mainly concerned with Cisco products and is quite marketing oriented. Cisco supported two types of wireless solutions one using autonomous access points, and one using lightweight (or dumb) access points in combination with WLAN controllers. The wired network infrastructure is the same for both types switches and routers. The Cisco Unified Wireless Network concept has five components that work together to create a complete network, from client devices to network infrastructure,...

VLANBased Attacks

VLAN-based attacks include VLAN hopping, in which a station is able to access a VLAN other than its own. This can be done with switch spoofing or with 802.1Q double-tagging. Switch spoofing involves a station configured to negotiate a trunk link between itself and the switch. By default, switches dynamically negotiate trunking status using Dynamic Trunking Protocol (DTP). If a computer is able to use DTP to establish a trunk link to the switch, it will receive all traffic bound for VLANs...