Link Aggregation Protocols
For performance reasons, it is sometimes required to bind several parallel links into a single aggregated bundle. The intent is to have a link with more bandwidth. Figure 11-5 shows such a bundling where two links are used between switch A and switch B. If the links were 1 Gbps links, the aggregated bandwidth would be 2 Gbps. In Cisco switches, this mechanism is called EtherChannel.
Figure 11-5 Aggregating Multiple Links
Figure 11-5 Aggregating Multiple Links
Aggregated Link
Switch A
Aggregated Link
Switch A

- Switch B
The EtherChannel (aggregated link) behaves like a link per itself. Spanning Tree Protocol (STP) runs on the aggregated link and not on the physical ports themselves. The aggregated link also has its own MAC address (which is typically identical to one of the physical ports). The switches use specific load-balancing mechanisms to spread the traffic load among all physical ports.
Two protocols exist to achieve such an aggregation:
• Port Aggregation Protocol (PAgP). Cisco proprietary protocol
• Link Aggregation Control Protocol (LACP). Standardized by the IEEE 802.3ad6
Figure 11-6 shows the packet structure for Cisco PAgP. The packets are sent to the Cisco Ethernet multicast address of 0100.0CCC.CCCC (the same as CDP and VTP) with SNAP encapsulation with the protocol identifier 01-04. The packet contains information about the local port and the partner port (MAC address, port identifier—Cisco devices use the SNMP ifindex capabilities). Additional information about system name and port name are added. There is neither an authentication mechanism or an integrity one.
Figure 11-6 Content of PAgP Packet
|
Field |
Content |
|
Header |
Version and Flags |
|
Local Device |
Device ID Learn Capability Hot Standby Priority Port Ifindex Group Capability Group Ifindex |
|
Partner Device |
Device ID Learn Capability Hot Standby Priority Port Ifindex Group Capability Group Ifindex Count |
|
TLV |
Device Name Port Name Reserved |
Figure 11-7 shows the IEEE 802.3ad LACP protocol data unit (PDU). LACP is part of the IEEE slow protocols—that is, protocols with a low throughput. The packets are sent to the Ethernet multicast address 0180.C200.0002 using the Ethertype of 88-09. It is merely a series of TLV-encoded fields about the actor (the local switch) and the partner. Just like PAgP, no security mechanism is built into LACP.
Figure 11-7 Link Aggregation Control PDU Format
32 Bits
Subtype= LACP 0x01
Version= 0x01
Actor Information TLV .
.. Partner Information TLV ...
Terminator TLV
Because there is little difference between PAgP and LACP from a security perspective, the next sections describe the risk analysis and the risk mitigation for both protocols. Both protocols are typically enabled by default on all trunk ports. Chapter 4, "Are VLANs Safe?," describes how an attacker might enable trunking on a port with the help of Dynamic Trunking Protocol (DTP).
Continue reading here: How Does a DoS Attack Differ from a DDoS Attack
Was this article helpful?