Detecting MAC Activity
To start with, many switches can be configured to warn the administrator about frequent MAC address moves. Example 2-8 shows the Cisco IOS configuration to enable this.
Example 2-8 Enabling MAC Address Moves Alarms on Cisco Switches
6K-1-720(config)# mac-address-table notification ?
mac-move Enable Mac Move Notification
6K-1-720(config)#mac-address-table notification mac-move ?
Although it is not going to stop an attack from occurring, MAC notification provides a pointer to a potentially suspicious activity. For example, in Example 2-9, the action on a Linux host triggers this MAC notification alert.
Example 2-9 MAC Spoofing Detected by MAC Notification
[root@client root]# ifdown eth1
[root@client root]# macchanger --mac 00:00:09:03:00:02 eth1
Current MAC: 00:00:00:20:00:00 (Xerox Corporation) Faked MAC: 00:00:09:03:00:02 (Xerox Corporation) [root@client root]# ifup eth1
Dec 23 22:08:19.108: %MAC_MOVE-SP-4-NOTIF: Host 0000.0903.0002 in vlan 20 is flapping between port Fa3/25 and port Gi1/15
Continue reading here: Unknown Unicast Flooding Protection
Was this article helpful?