Detecting MAC Activity

To start with, many switches can be configured to warn the administrator about frequent MAC address moves. Example 2-8 shows the Cisco IOS configuration to enable this.

Example 2-8 Enabling MAC Address Moves Alarms on Cisco Switches

6K-1-720(config)# mac-address-table notification ?

mac-move Enable Mac Move Notification

6K-1-720(config)#mac-address-table notification mac-move ?

Although it is not going to stop an attack from occurring, MAC notification provides a pointer to a potentially suspicious activity. For example, in Example 2-9, the action on a Linux host triggers this MAC notification alert.

Example 2-9 MAC Spoofing Detected by MAC Notification

[root@client root]# ifdown eth1

[root@client root]# macchanger --mac 00:00:09:03:00:02 eth1

Current MAC: 00:00:00:20:00:00 (Xerox Corporation) Faked MAC: 00:00:09:03:00:02 (Xerox Corporation) [root@client root]# ifup eth1

Dec 23 22:08:19.108: %MAC_MOVE-SP-4-NOTIF: Host 0000.0903.0002 in vlan 20 is flapping between port Fa3/25 and port Gi1/15

Continue reading here: Unknown Unicast Flooding Protection

Was this article helpful?

0 0