Link Aggregation Protocols

For performance reasons, it is sometimes required to bind several parallel links into a single aggregated bundle. The intent is to have a link with more bandwidth. Figure 11-5 shows such a bundling where two links are used between switch A and switch B. If the links were 1 Gbps links, the aggregated bandwidth would be 2 Gbps. In Cisco switches, this mechanism is called EtherChannel.

Figure 11-5 Aggregating Multiple Links

Figure 11-5 Aggregating Multiple Links

Aggregated Link

Switch A

Aggregated Link

Switch A

Switch B

The EtherChannel (aggregated link) behaves like a link per itself. Spanning Tree Protocol (STP) runs on the aggregated link and not on the physical ports themselves. The aggregated link also has its own MAC address (which is typically identical to one of the physical ports). The switches use specific load-balancing mechanisms to spread the traffic load among all physical ports.

Two protocols exist to achieve such an aggregation:

• Port Aggregation Protocol (PAgP). Cisco proprietary protocol

• Link Aggregation Control Protocol (LACP). Standardized by the IEEE 802.3ad6

Figure 11-6 shows the packet structure for Cisco PAgP. The packets are sent to the Cisco Ethernet multicast address of 0100.0CCC.CCCC (the same as CDP and VTP) with SNAP encapsulation with the protocol identifier 01-04. The packet contains information about the local port and the partner port (MAC address, port identifier—Cisco devices use the SNMP ifindex capabilities). Additional information about system name and port name are added. There is neither an authentication mechanism or an integrity one.

Figure 11-6 Content of PAgP Packet

Field

Content

Header

Version and Flags

Local Device

Device ID Learn Capability Hot Standby Priority Port Ifindex Group Capability Group Ifindex

Partner Device

Device ID Learn Capability Hot Standby Priority Port Ifindex Group Capability Group Ifindex Count

TLV

Device Name Port Name Reserved

Figure 11-7 shows the IEEE 802.3ad LACP protocol data unit (PDU). LACP is part of the IEEE slow protocols—that is, protocols with a low throughput. The packets are sent to the Ethernet multicast address 0180.C200.0002 using the Ethertype of 88-09. It is merely a series of TLV-encoded fields about the actor (the local switch) and the partner. Just like PAgP, no security mechanism is built into LACP.

Figure 11-7 Link Aggregation Control PDU Format

32 Bits

Subtype= LACP 0x01

Version= 0x01

Actor Information TLV .

.. Partner Information TLV ...

Terminator TLV

Because there is little difference between PAgP and LACP from a security perspective, the next sections describe the risk analysis and the risk mitigation for both protocols. Both protocols are typically enabled by default on all trunk ports. Chapter 4, "Are VLANs Safe?," describes how an attacker might enable trunking on a port with the help of Dynamic Trunking Protocol (DTP).

Continue reading here: How Does a DoS Attack Differ from a DDoS Attack

Was this article helpful?

0 0