Management Plane Attacks

Attacking the management plane to gain control of a switch results in an attacker's being able to gain control of the switch. He then can shut down interfaces, change the forwarding of traffic within the network, and cause all kinds of other problems.

However, if the switch's management plane is correctly secured, an attacker should never be able to gain access to the device.

Here are the recommended actions:

• Use out-of-band management (dedicated hardware interfaces for management plane traffic), if possible.

• Only allow management traffic from special subnets/hosts.

• Use encryption for all management traffic (SSH and SNMPv3).

• Use authentication, authorization, accounting (AAA).

• Enable syslog/SNMP traps to monitor all management plane activity.

Because management plane traffic is often treated in the same manner as control plane traffic, attacking the management plane can cause problems with critical control plane traffic.

For example, attacking the SSH server on a switch by flooding it with packets on TCP port 22 might fill up the switch channel from the switching fabric to the central CPU, which causes a drop of control plane packets (because of congestion). As a side effect, this could make it very difficult or impossible to remotely manage the switch.

Continue reading here: Configuring Hardware Based CoPP on the Catalyst 6500

Was this article helpful?

0 0