CDP Flooding with L2TP Tunneling
In some cases, it is required to bridge a port on one switch to a port on a different switch, making the end-user equipment unaware that an underlying network connects the two switches. This, however, requires that control packets, such as CDP, STP, VTP, and others, tunnel through the network using Layer 2 Tunneling Protocol (L2TP).
What happens if you flood the switch while it is configured in this way?
By default, when a UNI port is configured for L2TP tunneling, the switch assigns a rate limiter to those protocols being tunneled, as Example 13-17 shows.
Example 13-17 Configuring L2TP Tunneling and Automatically Assigning a Policer
|
c3400#conf t |
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
c3400(config)#int |
fastEthernet 0/1 |
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
c3400(config-if)#l2protocol-tunnel cdp |
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
c3400#sh platform |
policer |
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
Policers assigned |
for CPU |
protection |
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
Feature |
Policer |
Physical |
Asic |
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
Index |
Policer |
Num |
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
Fa0/1 |
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
STP |
1 |
0 |
0 |
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
LACP |
2 |
26 |
0 |
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
8021X |
3 |
26 |
0 |
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
RSVD_STP |
4 |
26 |
0 |
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
PVST PLUS |
5 |
0 |
0 |
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
CDP |
6 |
0 |
Notice that the switch has now automatically assigned policer 0 to CDP, STP, PVST, VTP, L2, keepalives, IGMP, and L2PT. When you repeat the attack using Yersinia CDP flooding, almost no effect occurs on the switch because, even if it accepts the CDP packets, they are now rate-limited to an acceptable level, as Example 13-18 shows. Example 13-18 Switch Status During an Attack with Policers Active
These examples show that if the attacks arrive through the UNI ports, the switch's automated control plane security features stop most attacks. NOTE Using control plane security on the ME3400 works well to stop DoS attacks using the available protocols' policers. However, keep in mind that sometimes it takes only one packet to cause problems; therefore, implement other security functions that are available on the switch. If a customer port would have been configured as an NNI port, however, all rate limiters would have been disabled. This would leave the switch vulnerable to attack because it does not support software-based CoPP as a last-resort mitigation tool. For example, change the configuration on the port so that it is treated as an NNI port, as Example 13-19 shows. Example 13-19 Changing a Port Type to NNI c3400#conf t c3400(config)#int fastethernet0/1 c3400(config-if)#port-type nni c3400#sh platform policer cpu interface fastEthernet 0/1 Policers assigned for CPU protection c3400#conf t c3400(config)#int fastethernet0/1 c3400(config-if)#port-type nni c3400#sh platform policer cpu interface fastEthernet 0/1 Policers assigned for CPU protection
Now, no rate limiters are assigned to the port. (The value of 255 for a policer indicates no rate limiting in use.) Now, launch the same CDP attack as before, but now you get more dramatic results (see Example 13-20). Example 13-20 Switch Status During an Attack with No Policers Active c3400#sh proc cpu CPU utilization for five seconds: 87%/21%; one minute: 31%; five minutes: 28% 03:18:81650837284: %SYS-3-CPUHOG: Task is running for (19193)msecs, more than (2000)msecs (821/1),process = HLFM address learning process. -Traceback= 115A3E0 447150 4477C4 47FEFC 226F3C 227610 8C2CA0 8B9268 The switch skyrockets to a high CPU, which makes it unresponsive. It also starts to lose OSPF neighbors, which causes routing instabilities. Continue reading here: Configuring Switches Without Control Plane Protocols Was this article helpful? |
|||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||