Port Security
Multihost Mode
When you must include hubs in your network topology, multihost mode is available as an option. In general, multihost mode does not change the default operation for 802.1X, and it is available on all Catalyst switches. To enable multihost mode on a switch running Cisco IOS software, enter the following command The main difference between single-auth mode and multihost mode is that after a MAC address is authenticated and authorized, any number of MAC addresses behind a hub can access the...
DHCP Overview
RFC 2131 and RFC 2132 originally defined DHCP, with several RFC extensions augmenting its capabilities. (See http www.dhcp.org rfcs.html for an exhaustive list.) The primary purpose of DHCP is to dynamically assign IP addresses to requesters for a specified duration (called the lease time). DHCP clients request addresses from DHCP servers. In most cases, clients and servers are several hops apart and are separated by routers and other network devices. When that is the case, the first hop router...
DHCP Snooping Against Ipmac Spoofing Attacks
A switch can use the DHCP snooping bindings to prevent IP and MAC address spoofing attacks. MAC spoofing attacks, as Figure 5-7 shows, consist in malicious clients generating traffic by using MAC addresses that do not belong to them. The motivation behind a MAC spoofing attack is the potential ability to gain network access when access control is based on MAC information, for example. Received Traffic Source Address 10.1.1.3 MAC B Attacker Sends Packets with Spoofed Source MAC Address If...
What Does IPv6 Change
Actually, from the users' and routers' perspectives, little things change between IPv4 and IPv6. As Figure 7-1 shows, IPv4 and IPv6 can coexist in the same host or router. Both can run on Ethernet (different packet types multiplex them on the same data link), and both support the usual Layer 4 protocols, such as TCP or User Datagram Protocol (UDP). It is also easy for applications to support both protocols at the same time, such as Firefox or Microsoft Internet Explorer. Both browsers can...
Attack of the 8021Q Tag Stack
Nothing in the 802.1Q specification forbids multiple consecutive tags to be chained, thereby achieving a 802.1Q tag stack. Figure 4-3 represents a two-level 802.1Q tag stack. Double 802.1Q Stack 4 Bytes 4 Bytes Double 802.1Q Stack 4 Bytes 4 Bytes Source MAC Dot 1Q Dot 1Q EtherType 1 Ethernet Frame with Two 802.1Q Tags (Not to scale) Ethernet Frame with Two 802.1Q Tags (Not to scale) There are legitimate use cases for stacking multiple 802.1Q tags. One of them is Cisco QinQ, where up to 4096...
Disabling STP
As shown in Chapter 3, Attacking the Spanning Tree Protocol, STP can and should be disabled on an access port because an end host (workstation, printer, and so on) never sends IEEE 802.1d or 802.1w bridge protocol data units (BPDU). This can be done with the help of BPDU-guard IOS(config) interface FastEthernet 0 0 IOS(config-if) spanning-tree bpduguard enable CatOS> (enable) set spantree bpdu-guard 2 47 enable Spantree port 2 47 bpdu guard enabled. Chapter 3 demonstrated that a DoS attack...
Debugging Information
In most enterprise networks, L2TPv3 and xconnect are unusual. That being said, here is some debugging information for a working configuration. The information is limited to L2TP because all other debugging information is available for IPsec and IKE. Example A-1 displays some debugging information for L2TP's tunnels. The first command, show l2tun session circuit, displays all active tunnels with the peer. The second command, show l2tun session packets, prints some counters about the packets sent...
About the Contributing Authors
Rajesh Bhandari is a network security solutions architect with Cisco. He is responsible for defining a security architecture that incorporates standards-based techniques for building a secure network as part of Cisco's Self Defending Network initiative. At Cisco, Rajesh has also served as a technical leader in storage networking and as a software engineer on the Catalyst 6000 platform. Prior to joining Cisco in 1999, Rajesh was a software engineer in optical networking at Nortel Networks.
Let the Games Begin
Unfortunately, you are likely to come across LAN hackers that are intimately familiar with STP's inner workings. They also know that little or no attention is paid to STP security. They realize how gullible for lack of a better term the protocol actually is. STP attacks moved from the theoretical field to reality fairly recently. Black Hat Europe 2005 proposed a session that discussed various ways to exploit STP3. Packet-building libraries, such as libnet4, have been shipping C-source code to...
Link Aggregation Protocols
For performance reasons, it is sometimes required to bind several parallel links into a single aggregated bundle. The intent is to have a link with more bandwidth. Figure 11-5 shows such a bundling where two links are used between switch A and switch B. If the links were 1 Gbps links, the aggregated bandwidth would be 2 Gbps. In Cisco switches, this mechanism is called EtherChannel. Figure 11-5 Aggregating Multiple Links Figure 11-5 Aggregating Multiple Links The EtherChannel (aggregated link)...
Configuring Switches Without Control Plane Protocols
As shown in Chapter 12, Introduction to Denial of Service Attacks, a control plane in an Ethernet switch consists mainly of the following protocols L2 processing. A switch must process and respond to Spanning Tree Protocol (STP), Link Aggregation Control Protocol (LACP), Port Aggression Protocol (PAgP), IEEE 802.1X, Cisco Discovery Protocol (CDP), Dynamic Trunking Protocol (DTP), VLAN Trunking Protocol (VTP), and keepalive packets. Internet Control Message Protocol (ICMP). ICMP packets must be...
Integration Value Add of 8021X
Data traffic originating from an end station is disallowed until 802.1X completes. A LAN segment, as previously shown, is comprised of exactly two ports. An authenticator can monitor an operational state and detect the presence of an active device at the remote end of the link or when an active device becomes inactive. Along with link state, these events trigger changes in the authorization state of the switch port. This process is a default condition, and it is demonstrated through port...
Port Security
Port security allows the switch's administrator to limit the number of MAC addresses that can appear on a given LAN port. The limit can be manually set or the switch can be instructed to lock down on the first dynamically learned address. It's usually possible to save the list of addresses dynamically learned so they can survive a reboot. When a port-security violation is detected, several actions can ensue. The port can be brought down when more than n MAC addresses show up or traffic from an...
Elements of an ARP Spoofing Attack
An attack consists of sending fake unsolicited ARP replies to host A, as Figure 6-4 shows. The attacker, host C, sends this gratuitous ARP without any MAC spoofing to host A. The content contains a new but incorrect mapping of host B's IP address to the MAC address of host C (the attacker). MAC 0666 -> CAFE 10.0.0.2 is at 0666 MAC 0666 -> CAFE 10.0.0.2 is at 0666 Host C IP 10.0.0.3 MAC 0000.0666.0000 Upon receipt of the faked gratuitous ARP reply, host A updates its ARP table with the new...
MAB Operation
As indicated in preceding sections for 802.1X deployments, only EAPOL control frames are typically processed by switch ports while 802.1X is maintained in an operating and active state. However, this also means that MAC addresses from any edge device might not be known until EAPOL frames are processed from it. These are the security benefits of 802.1X, and they do not change in any way with respect to any MAB implementation. Because it is noteworthy to this discussion, spanning tree is not even...
Introducing the macof Tool
Today, various tools can perform MAC flooding attacks. These tools include Ettercap3, Yersinia4, THC Parasite5, and macof. Macof is efficient and extremely simple to use. Example 2-1 presents its manual page. macof - flood a switched LAN with random MAC addresses SYNOPSIS macof -i interface -s src -d dst -e tha -x sport -y dport -n times macof floods the local network with random MAC addresses (causing some switches to fail open in repeating mode, facilitating sniffing). A straight C port of...
CDP Risk Analysis
The most obvious risk associated with CDP is the information leak that is, an attacker learns a lot by listening to CDP. This attack is purely passive there is no way to detect this information leak, and it causes no damage to the network. Many sniffing tools have the ability to decode CDP, such as Yersinia1 (shown in Figure 11-2), but there are also generic sniffers, such as Ethereal. Figure 11-2 CDP Packet Decode by Yersinia Figure 11-2 CDP Packet Decode by Yersinia After a maximum of 60...
Diving Deep into VRRP
This section provides more detailed information on VRRP, as described in RFC 23381 and RFC 37682. VRRP runs on top of IP using Protocol 112. Packets are sent to multicast address 224.0.0.18 with TTL 255. Routers use their actual IP address as the source address for protocol packets, not the virtual IP address. NOTE A lot of information about VRRP exists on the web and in books, as described in RFC 2338 and RFC 3768. Only the master router sends periodic VRRP messages by using the virtual MAC...
Not Just Theory
A switch (6K-4-S2) has just been MAC attacked. Its bridging table is full. The switch has a routed interface in VLAN 20. Pings to 10.20.20.1 (a remote router) are successful. The Address Resolution Protocol (ARP) table reveals that the MAC address associated to 10.20.20.1 is 0000.0020.0000. However, no entry for that address exists in the bridging table This means that all traffic destined to 0000.0020.0000 is flooded to all ports that are members of VLAN 20. Example 2-6...
HSRP Mechanics
HSRP's role is to make a group of Layer 2 adjacent routers appear as a single virtual router. One physical router, known as the active router, actually works and forwards IP packets. The other physical routers, known as standby routers, basically do nothing but keep the HSRP states. When the active router fails, a standby router automatically takes over the active role that is, it starts forwarding the hosts' packets. NOTE HSRP is not a routing protocol. Its main application is for hosts who...
Discovering VRRP
Even if you are familiar with how VRRP works, feel free to read on to refresh your knowledge or to gather new information, because this section focuses on specific points linked to the security aspects of VRRP. In VRRP, each physical router has its own MAC and IP addresses, but it also shares one MAC address and one IP address for the virtual router. Figure 10-1 depicts such a topology when the VRRP group consists of two routers. There is a change in the terminology compared to HSRP Master...
Symmetric Cryptosystems
Symmetric cryptosystems use the same key material for all operations (that is, the same key to encrypt and decrypt). Symmetric cryptosystems include symmetric encryption and message authentication with the help of hashes. Symmetric encryption occurs when the same key is used for both encryption and decryption, as Figure 1-5 shows. This key is called the shared key or session key. Networks use multiple symmetric encryption algorithms the more recent Advanced Encryption Standard (AES), the older...
TTL Expiry Attack
When a packet expires on a routing platform because its TTL reaches 0, it is required to send an ICMP TTL Exceeded message back to the sender (RFC 17162). This functionality can, however, be misused. If an attacker sends a flood of packets with the TTL value set such that the packets expire on the switch, the switch is forced to generate a large amount of ICMP TTL Exceeded messages. This causes a high CPU load. Regarding TTL expiry attacks, what is really troubling is that an attacker can be...
Discovering Extensible Authentication Protocol
Port-based network access control uses the physical access characteristics of IEEE 802 LAN infrastructures. These infrastructures leverage the Extensible Authentication Protocol (EAP) to carry arbitrary authentication information, not the authentication method itself. EAP is an encapsulation protocol with no dependency on IP, and it can run over any link layer, including IEEE 802 media. EAP transports authentication information in the form of EAP payloads. EAP also establishes and manages the...
Keeping Insiders Honest
It is important to understand the intersection of port-based access-control solutions and related policy-enforcement mechanisms. It is too easy for an unsecured individual to gain physical and logical access to a network. A solution to this problem is 802.1X, which keeps the outsiders out and can serve as a way to extend the level of trust in a networked system by proving someone's identity. As a potential benefit, the network now becomes aware of authorized sessions, and it can enforce...
BPDU Filtering
There is actually another method to discard incoming and outgoing BPDUs on a given port BPDU filtering. This feature silently discards both incoming and outgoing BPDUs. Although extremely efficient against a brute-force DoS attack, BPDU filtering offers an immense potential to shoot yourself in the foot. Enable this feature on the incorrect port, and any loop condition goes undetected forever, which causes instantaneous network downtime. On the other hand, not sending out BPDUs is actually a...
STP Operation More Details
To understand the attacks that a hacker is likely to carry out against STP, network administrators must gain a solid understanding of STP's inner workings. The protocol builds a loop-free topology that looks like a tree. At the base of the tree is a root bridge an election process takes place to determine which bridge becomes the root. The switch with the lowest bridge ID (a concatenation of a 16-bit user-assigned priority and the switch's MAC address) wins. The root-bridge election process...
Configuring Software Based CoPP
Creating a CoPP policy requires a good understanding of which control plane and management plane protocols and services are in use. In addition, you must understand the packet rate that those protocols and services require. Too low a value for a rate limit can cause problems with passing normal traffic, and too high a value can allow attacks to slip through. The recommended method to develop a good CoPP policy is to separate the different protocols and services into groups based on relative...
Telnet Flooding with CoPP
Numerous alternatives exist to protect against attacks on the management plane. One option is to ensure that only traffic from prevalidated IP addresses is allowed (only allow packets from the management network). A second option is to implement a CoPP policy to protect the services on the management plane. In this example, a simple CoPP policy is created to protect Telnet (TCP port 23) and SSH (TCP port 22). First, create an access list that specifies the traffic we want to inspect access-list...
Motivation for IPv6
In 1994, the Internet Engineering Task Force (IETF) began work on a new version of IP. The motivation was to ensure that the Internet could still grow at a fast pace while keeping it running, scalable, and stable. One of the means to keep the Internet, as we know it, was to specify a brand-new network layer protocol to replace IP. In 1995, this new protocol received the name IPv6. NOTE Wonder why IP jumped from the current version, IPv4, to the next one, IPv6, and apparently skipped the...
IEEE 8021Q Overview
What is a VLAN The answer is simple It is a broadcast domain. In other words, a VLAN defines how far a broadcast packet can radiate. Assuming no routing is involved, traffic entering a physical LAN switch port configured to be part of a given VLAN is constrained to other ports that are also members of that VLAN. VLANs offer a practical and easy way to implement network segmentation at Layer 2 of the Open Systems Interconnection (OSI) model. A VLAN is primarily identified by a user-defined...
Exploring IEEE 8021X
The IEEE 802.1 working group developed the 802.1X standard. It is a framework that addresses and provides port-based access control using authentication. Primarily, 802.1X is an encapsulation definition for EAP over IEEE 802 media. The Layer 2 protocol transports EAP authentication messages between a client device and a network device. 802.1X typically assumes a secure connection, and the enforcement of sessions are imposed through MAC-based filtering and port-start monitoring. To provide...
Diving Deep into CDP
CDP does not run over IP, but it runs directly over the data link layer. When Ethernet is used, the IEEE 802.3 and IEEE 802.1 encapsulation are used rather than the usual Ethernet II direct encapsulation (which IPv4 uses). The Subnetwork Access Protocol (SNAP) is used. SNAP consists of 3 bytes of Logical Link Layer header (typically AA-AA-03), followed by the Cisco Organizational Unique Identifier (OUI) 00-00-0C, and the CDP identifier 20-00. Figure 11-1 displays the CDP packet format. The...
IEEE Link Layer Discovery Protocol
IEEE has specified IEEE 802.1AB, also known as Link Layer Discovery Protocol (LLDP3), which is similar in goal and design to CDP. Some differences include the following Multicast MAC address. Address is 0180.C200.000E. Ethernet type. LLDP does not use SNAP encapsulation instead, it uses Ethernet II framing with 88-CC as the Ethernet type. Packet format. As Figure 11-3 shows, the packet format consists of several fields encoded as < Tag, Length, Value> (TLV) with the first three and the last...
Current State Authentication with 8021X
This section describes how 802.1AE and 802.1af extend the existing IEEE 802.1X protocol to provide continuous data protection in addition to authentication. To fully understand and appreciate the LinkSec security architecture, you must understand what LinkSec is and its key components you must also identify the current state of network security at the link layer and how LinkSec extends it to build a robust security mechanism for the entire enterprise network. As Chapter 17, Identity-Based...
Securing Networks with RMON
Remote Monitoring (RMON) is a specific SNMP Management Information Base (MIB) for remote monitoring and management of network equipment. MIB is standardized at the IETF as RFC 20216 and RFC 28197. It transforms every RMON-capable network device into a remote protocol analyzer. Different pieces of information can be collected Host. Related to each host discovered in the network by keeping MAC addresses captured in promiscuous mode. Matrix. Used for conversations between sets of two addresses....
Summary Cya
Several ancillary protocols are used in an Ethernet environment, such as CDP and VTP or LLDP and LACP. Automatic discovery protocols, such as CDP or LLDP, allow an NMS to discover the complete network as well as automatic configuration of some devices, such as IP phones. Both of them present some risks (mainly an information leak, which an attacker could leverage) therefore, they should be disabled on all ports but the uplinks and ports to other network devices (including IP phones). VTP is...
Introducing DHCP Snooping
DHCP snooping is a control plane feature that closely monitors and restricts DHCP operations on a VLAN. Control plane means the feature runs on the central management processor where it is possible to perform deep-packet inspection operations. DHCP snooping introduces the concept of trusted and untrusted ports inside a given VLAN. NOTE For a quick review of the steps involved in a typical DHCP operation, review the beginning of this chapter DORA (Discover Offer Request Ack). Hosts have no...
DHCP Message Validation
For messages received on trusted ports, no validation is performed. For messages received on untrusted ports, the following steps are taken 1 DHCP messages normally exchanged from a DHCP server to a client are dropped. These messages are DHCPOFFER, DHCPACK, and DHCPNAK. 2 DHCP messages with a nonzero relay agent gateway IP address (also called giaddr field) or Option 82 data are dropped. 3 DHCPRELEASE DHCPDECLINE messages are verified against the binding-table entries to prevent a host from...
Working with VACL
VLAN-based ACLs made their introduction on LAN switches some time after RACLs. VACLs provide the capability to filter traffic between hosts located in the same VLAN. They apply to IP and non-IP traffic alike. For example, using VACLs, it is possible to permit or deny traffic based on its source or destination MAC address. Naturally, IP addresses, User Datagram Protocol (UDP), and TCP ports can also be used as a selection criteria. Contrary to a VACL, a RACL cannot match intra-VLAN traffic...
Protecting the Infrastructure Using ACLs
In an effort to protect switches and routers from various risks both accidental and malicious infrastructure-protection ACLs need to be deployed at network ingress points. These ACLs deny access from external sources to all infrastructure addresses, such as router interfaces. At the same time, these ACLs permit legitimate transit traffic to flow uninterrupted through the infrastructure. A common set of ACLs consists of filtering addresses that have no business entering the network. Those are,...
Combining IPsec with L2TPv3 for Secure Pseudowire
As described in Chapter 18, IEEE 802.1AE, IEEE 802.1AE protects all Layer 2 traffic with encryption and authentication. Not all existing switches support IEEE 802.1AE therefore, in the short term, an alternative solution might be attractive. This solution relies on IPsec for the security features. Although IPsec is convenient and suitable to protect IP traffic, it sometimes requires you to also protect all Layer 2 communication between two sites, such as spanning a LAN over a confidential...
Dynamic ARP Inspection
Chapter 5, Leveraging DHCP Weaknesses, explained that Layer 3 switches can inspect DHCP traffic to prevent attacks against the DHCP. DHCP snooping also means that the switch now knows the < IP, MAC> mapping for all hosts using DHCP. With this correct mapping knowledge, the switch can inspect all ARP traffic and check whether the information inside the ARP replies is valid if it's not, the switch simply drops the ARP packet. This technique is called Dynamic ARP Inspection (DAI). NOTE DAI...
How Does a DoS Attack Differ from a DDoS Attack
A distributed denial of service attack (DDoS) is defined as follows A distributed denial of service attack (DDoS) occurs when a device or service is being attacked by multiple attackers. The attacks usually consists of bandwidth-flooding attacks or resource-starvation attacks. Simply said, the goal of a DDoS attack is to make the targeted system's services unavailable to legitimate users by using flooding (where users are unable to reach the service) or resource starvation (where the service...
Unknown Unicast Flooding Protection
Some switches ship with a mechanism that can protect an entire VLAN from unicast flooding's negative effects. This mechanism is known as unicast flood protection. As already shown, when no entry corresponds to a frame's destination MAC address in the incoming VLAN, the frame is sent to all forwarding ports within the respective VLAN, which causes flooding. Limited flooding is part of the normal switching process, but continuous flooding causes adverse performance effects on the network. The...
Hardware Rate Limiters
The hardware rate limiters are primarily used to control traffic where an ACL cannot be used. Examples of this are IP options, Time to Live (TTL), and maximum transmission unit (MTU) failures, and other special cases. It is possible to specify up to 32 different rate limiters, but some of them share one of the physical rate limiters. Ten physical rate limiters are available, 2* Layer 2 and 8* General Unicast Multicast . To see which hardware rate limiters are active, use the command shown in...
Stateless Configuration with Router Advertisement
IPv6 has a stateless configuration mode to make the end node's configuration easier (especially with mobile nodes). It's called stateless because it does not act like DHCP, where there's an actual four-step protocol exchange between the DHCP client and the DHCP server. DHCP consists of four different steps as described in Chapter 5 Step 1 The end node sends a broadcast DHCP DISCOVER message and hopes to reach at least one DHCP server. Step 2 All DHCP servers reply with a DHCP OFFER message to...
Understanding Cisco VTP
The preceding section briefly alluded to another LAN protocol called VTP. VTP reduces administration overhead in a switched network. With VTP, when you configure a new VLAN on a switch designated as a VTP server, information regarding that VLAN is distributed to all switches in the VTP domain, thereby removing the need to manually configure each switch one by one. You can configure a switch to operate in one of four different VTP modes Server. Here, you can create, modify, and delete VLANs and...
CDP Flooding with L2TP Tunneling
In some cases, it is required to bridge a port on one switch to a port on a different switch, making the end-user equipment unaware that an underlying network connects the two switches. This, however, requires that control packets, such as CDP, STP, VTP, and others, tunnel through the network using Layer 2 Tunneling Protocol (L2TP). What happens if you flood the switch while it is configured in this way By default, when a UNI port is configured for L2TP tunneling, the switch assigns a rate...
Mounting an ARP Spoofing Attack
Multiple hacking tools exist to mount an ARP spoofing attack, including the following dsniff. The first tool made available, arpspoof, was part of the dsniff package. It has no GUI and is available on most Linux and Windows platforms. ettercap.3 A generic sniffer that has an ARP spoofing module. It has a GUI and is available on Linux and Windows platforms. cain.4 A sniffer designed by and for hackers. (It contains a utility to detect passwords in IP packet flows.) It runs only in Microsoft...
Intrusion Detection
Because ARP spoofing requires an attacker to send traffic, network IDSs can detect this attack. Cisco network IDS5 has a few signatures related to ARP spoofing based on the ATOMIC.ARP engine. A free tool, ARPwatch6, can detect an ARP spoofing attack. Typically, ARPwatch runs on a Linux host and processes all ARP packets on an attached Ethernet segment. ARPwatch executes multiple checks on the ARP packets Is it a malformed packet Is it a new MAC address (this is a MAC address never seen on the...
Using Strong Authentication
The easiest way to partly mitigate an HSRP attack is to use strong authentication. Cisco routers and switches running 12.3(2)T and above can use a message digest algorithm 5 (MD5) Hash Message Authentication Code (HMAC) to authenticate all HSRP packets without ever sending the key in the clear. Example 9-1 shows the syntax when you use a chain of preshared keys Each key has a send lifetime (when this key sends HSRP messages) and an accept lifetime (when this key checks the validity of received...
MAC Authentication Primer
MAC address authentication itself is not a new idea. One classic flavor of this is port security. Another flavor is the Cisco VLAN Management Policy Server (VMPS) architecture. With VMPS, you can have a text file of MAC addresses and the VLANs to which they belong. That file gets loaded into the VMPS server switch through TFTP. All other switches then check with the VMPS server switch to see which VLAN those MAC addresses belong to after being learned by an access switch. Also, you can define...
Hijacking Traffic Using DHCP Rogue Servers
Another DHCP exploit with devastating results consists in installing a covert DHCP server on a LAN segment, as Figure 5-4 shows. IP Address 10.10.10.101 Subnet Mask 255.255.255.0 Default Routers 10.10.10.1 DNS Servers 192.168.10.4, 192.168.10.5 Lease Time 10 Days If a rogue DHCP server is installed on the LAN, by default, it receives DHCPDISCOVER messages from clients seeking to acquire an IP address. IP Address 10.10.10.101 Subnet Mask 255.255.255.0 Default Routers 10.10.10.1 DNS Servers...
Working with Devices Incapable of 8021X
Today, 802.1X is the recommended port-based authentication method at the access layer in enterprise networks. However, not all devices have an 802.1X-supplicant capability embedded into their operating system (OS). For example, most printers, IP phones, fax machines, and so on do not have this capability, but they still need to be allowed into the network even without 802.1X authentication. A supplemental authentication technique should be employed as the basis of the nonresponsive host issue...
Anatomy of a Switch
A simplified view of a switch is that it has a central CPU and special forwarding ASICs. The CPU is responsible for building up the forwarding tables and allowing ASICs to perform forwarding in hardware, which makes switching an efficient process. Figure 12-2 shows the architecture of a typical LAN switch. Figure 12-2 shows the architecture of a typical LAN switch. Some high-end switches use distributed forwarding architecture, using numerous dedicated CPUs to control the forwarding logic on...
Layer 2 PDU Rate Limiter
Available only on certain switches, such as the Supervisor Engineer 720 for the Catalyst 6500, a third option to stop the DoS from causing damage exists. It takes the form of a hardware-based Layer 2 PDU rate limiter. It limits the number of Layer 2 PDUs (BPDUs, DTP, Port Aggregation Protocol PAgP , CDP, VTP frames) destined for the supervisor engine's processor. The feature works only on Catalyst 6500 7600 that are not operating in truncated mode. The switch uses truncated mode for traffic...
Introducing Spanning Tree Protocol
Chapter 2, Defeating a Learning Bridge's Forwarding Process, explained how Ethernet switches build their forwarding tables by learning source MAC addresses from data traffic. When an Ethernet frame arrives on a switch port in VLAN X with a destination MAC address for which there is no entry in the forwarding table, the switch floods the frame. That is, it sends a copy of the frame to every single port in VLAN X (except the port that originally received the frame). Although this is perfectly...
Technology Behind Fast ACL Lookups
How do modern LAN switches perform ACL lookups millions of times per second An ACL lookup is, in and out of itself, a rather simple operation IPv4 packets adhere to a well-defined binary packet format, with fixed-size addresses always found at the same offset. Because IPv4 addresses are specified using just 4 bytes, searching for a specific address requires just a few operations when the proper data structure is used. Most algorithm-based software solutions for address lookups employ data...
Forcing an Excessive Flooding Condition
If a switch does not have an entry pointing to a destination MAC address, it floods the frame. What happens when a switch does not have room to store a new MAC address And what happens if an entry that was there 2 seconds ago was just overwritten by another entry These questions are probably what Ian Vitek must have asked himself back in 1999 when he wrote a little tool called macof (later ported to C by Dug Song).2 How switches behave when their bridging table is full depends on the vendor....
Gratuitous ARP
When ARP was designed, the Ethernet adapters were not reliable. Then, when a host had a new MAC address because its Ethernet adapter was replaced, it should have sent an unsolicited ARP reply to force an update on all ARP tables in the other hosts. In Figure 6-3, host B changes its MAC address to 0000.BABE.0000 and sends an unsolicited ARP reply to the broadcast address FFFF.FFFF.FFFF to tell hosts on the Ethernet segment to change their < IP, MAC> binding for host B. Host C IP 10.0.0.3 MAC...
Ethernet Frame Formats
For mostly historical reasons, Ethernet frames come in various shapes and forms, but they all convey the same information where the frame originated, where it is destined to, what payload it carries, and a checksum to verify data integrity. Today, essentially two slightly different frame formats exist EthernetV2 and IEEE 802.3. It is difficult to authoritatively assess the proportion of EthernetV2 versus 802.3 in today's network a rough estimate would probably call for 80 percent EthernetV2 for...
Common Flooding Attacks
The most common attack, called the TCP SYN attack, floods the service with TCP SYN packets. For each SYN packet received, the server allocates resources for a new incoming session and sends back a TCP ACK packet. An attacker simply ignores this (or the source address was spoofed, so the reply goes to max hop-count oblivion on the Internet). After a while, the server runs out of session resources and stops answering requests. Variants of the TCP SYN attack disrupt other TCP states, such as...
Increasing Security with Net Flow Applications
Using a security-monitoring application, such as Cisco Security Monitoring, Analysis, and Response System3 (CS-MARS), makes using NetFlow easier and more readable. Indeed, CS-MARS can receive NetFlow export datagrams from multiple switches, and it can build graphs like the one shown in Figure 15-2. It can even have a rule that triggers an alert when predefined thresholds are crossed. Figure 15-2 shows baseline traffic, where the peak is simply the normal traffic increase during work hours....
Enabling Net Flow on a Catalyst 6500
The Catalyst 6500 separates the data collection configuration from the NetFlow data export (NDE) to collectors. Example 15-1 shows a basic configuration of NetFlow on Cisco IOS. NOTE The NetFlow configuration contains more options, such as allowing the supervisor the ability to build a flow cache entry for switched frames (that is, not only for routed ones). Example 15-1 Configuring NetFlow on Catalyst 6500 and Cisco IOS IOS(config) mls flow ip interface-full IOS(config) mls flow ipv6...
Telnet Flooding Without CoPP
To demonstrate what can happen when a Catalyst 6500 is attacked without CoPP enabled, a flooding attack against TCP port 23 (Telnet) was started using the hping31 utility. Running on an average PC platform using SuSe Linux, the hping3 utility generated about 110,000 pps, which would not be a problem for the 6500 in normal situations. However, because Telnet packets are destined to the management plane, they are forwarded directly to the central CPU where they are processed. In this case, the...
Normal ARP Behavior
Figure 6-1 ARP Request in a Broadcast Frame CAFE -> FFFF.FFFF.FFFF Who is 10.0.0.2 CAFE -> FFFF.FFFF.FFFF Who is 10.0.0.2 Host C IP 10.0.0.3 MAC 0000.0666.0000 Host C IP 10.0.0.3 MAC 0000.0666.0000 All hosts on the same Ethernet LAN or VLAN receive the ARP request and process it. Only host B reacts on the ARP request because its IP address, 10.0.0.2, matches the IP address inside the ARP request. As Figure 6-2 shows, host B sends a solicited ARP reply to host A. This frame contains the...
Exploring TCAM
A TCAM is a content-addressable memory where each bit is allowed to store a 0, 1, or a don't-care value the ternary qualification comes from the fact that three different types of values can be stored. You can think of a CAM as a reverse random-access memory Data is provided and an address is returned. Don't care bits play an important role in ACL lookups because ACLs frequently ignore portions of an IP address. For example, if an ACL is interested in matching traffic from 192.168.2.0 24, it...
Defending Against Burning Attacks
There is no way to protect a non-PES from a burning attack, even if the static configuration of the wattage can help limit the damage to the attached device. The burning attack requires physical access to inject the signaling to force 42 V into the CAT5 cable. If an attacker has access to the cable, he can also inject 110-220 V into it, which causes more damage in the PES. Therefore, the risk of this attack does not increase by enabling PoE on the port. NOTE A related issue is when a powered...























