CDP Flooding with L2TP Tunneling

In some cases, it is required to bridge a port on one switch to a port on a different switch, making the end-user equipment unaware that an underlying network connects the two switches. This, however, requires that control packets, such as CDP, STP, VTP, and others, tunnel through the network using Layer 2 Tunneling Protocol (L2TP).

What happens if you flood the switch while it is configured in this way?

By default, when a UNI port is configured for L2TP tunneling, the switch assigns a rate limiter to those protocols being tunneled, as Example 13-17 shows.

Example 13-17 Configuring L2TP Tunneling and Automatically Assigning a Policer

c3400#conf t

c3400(config)#int

fastEthernet 0/1

c3400(config-if)#l2protocol-tunnel cdp

c3400#sh platform

policer

cpu interface fastEthernet 0/1

Policers assigned

for CPU

protection

Feature

Policer

Physical

Asic

Index

Policer

Num

Fa0/1

STP

1

0

0

LACP

2

26

0

8021X

3

26

0

RSVD_STP

4

26

0

PVST PLUS

5

0

0

CDP

6

0

Example 13-17 Configuring L2TP Tunneling and Automatically Assigning a Policer (Continued)

DTP

7

26

0

UDLD

8

26

0

PAGP

9

26

0

VTP

10

0

0

CISCO_L2

11

0

0

KEEPALIVE

12

0

0

CFM

13

255

0

SWITCH_MAC

14

26

0

SWITCH_ROUTER_MAC

15

26

0

SWITCH_IGMP

16

0

0

SWITCH_L2PT

17

0

0

Notice that the switch has now automatically assigned policer 0 to CDP, STP, PVST, VTP, L2, keepalives, IGMP, and L2PT.

When you repeat the attack using Yersinia CDP flooding, almost no effect occurs on the switch because, even if it accepts the CDP packets, they are now rate-limited to an acceptable level, as Example 13-18 shows.

Example 13-18 Switch Status During an Attack with Policers Active

c3400#sh proc cpu

CPU utilization for five seconds: 4%/0%; one minute: 5%; c3400#sh policer cpu uni drop

five minutes: 7%

Port In Dropped Name Frames Frames

Fa0/1 484 183857

c3400#sh policer cpu uni drop interface fastEthernet 0/1

Policer assigned for Fa0/1

Protocols using this policer:

"CDP" "CISCO_L2" "KEEPALIVE" "SWITCH_ROUTER_MAC" "SWITCH_L2PT" Policer rate: 8000 bps

'SWITCH_IGMP"

In frames: 484 Dropped frames: 183857

These examples show that if the attacks arrive through the UNI ports, the switch's automated control plane security features stop most attacks.

NOTE Using control plane security on the ME3400 works well to stop DoS attacks using the available protocols' policers. However, keep in mind that sometimes it takes only one packet to cause problems; therefore, implement other security functions that are available on the switch.

If a customer port would have been configured as an NNI port, however, all rate limiters would have been disabled. This would leave the switch vulnerable to attack because it does not support software-based CoPP as a last-resort mitigation tool.

For example, change the configuration on the port so that it is treated as an NNI port, as Example 13-19 shows.

Example 13-19 Changing a Port Type to NNI

c3400#conf t c3400(config)#int fastethernet0/1 c3400(config-if)#port-type nni c3400#sh platform policer cpu interface fastEthernet 0/1

Policers assigned for CPU protection c3400#conf t c3400(config)#int fastethernet0/1 c3400(config-if)#port-type nni c3400#sh platform policer cpu interface fastEthernet 0/1

Policers assigned for CPU protection

Feature

Policer

Physical

Asic

Index

Policer

Num

Fa0/1

STP

1

255

0

LACP

2

255

0

8021X

3

255

0

RSVD_STP

4

255

0

PVST_PLUS

5

255

0

CDP

6

255

0

DTP

7

255

0

UDLD

8

255

0

PAGP

9

255

0

VTP

10

255

0

CISCO_L2

11

255

0

KEEPALIVE

12

255

0

CFM

13

255

0

SWITCH_MAC

14

255

0

SWITCH_ROUTER_MAC

15

255

0

SWITCH_IGMP

16

255

0

SWITCH_L2PT

17

255

0

Now, no rate limiters are assigned to the port. (The value of 255 for a policer indicates no rate limiting in use.)

Now, launch the same CDP attack as before, but now you get more dramatic results (see Example 13-20).

Example 13-20 Switch Status During an Attack with No Policers Active c3400#sh proc cpu

CPU utilization for five seconds: 87%/21%; one minute: 31%; five minutes: 28% 03:18:81650837284: %SYS-3-CPUHOG: Task is running for (19193)msecs, more than

(2000)msecs (821/1),process = HLFM address learning process. -Traceback= 115A3E0 447150 4477C4 47FEFC 226F3C 227610 8C2CA0 8B9268

The switch skyrockets to a high CPU, which makes it unresponsive. It also starts to lose OSPF neighbors, which causes routing instabilities.

Continue reading here: Configuring Switches Without Control Plane Protocols

Was this article helpful?

0 0