VTP Risk Analysis
Having a protocol that is able to add or remove VLAN from a network is incredibly powerful, yet dangerous. Indeed, if this protocol is not secure, an attacker might run a DoS attack by disabling a VLAN. A less obvious DoS attack might be run by enabling a VLAN on all the switches, therefore increasing the amount of forwarded multicast and broadcast traffic across all switches.
NOTE Spanning a VLAN across multiple switches is usually considered bad design because there will be too many forwarded multicast or broadcast frames among multiple switches (as well as unknown destination frames, which are also flooded on all switches for a VLAN). To limit this undesirable traffic to a minimum, modern campus designs keep the broadcast domains as small as possible. A sound design limits a VLAN within a Layer 3 switch's network by routing IP packets rather than switching Layer 2 frames. This design is possible nowadays because most applications run over IP. This also means that VTP has limited usefulness in modern networks.
VTP version 3 includes several features that, when correctly deployed, reduce the risk close to zero:
• Per Port Configuration. VTP should only be enabled on trusted ports—that is, ports connected to other switches in your management domain (such as in a wiring closet, but not in a meeting room).
• HMAC Authentication. Because an attacker does not know the preshared key, the MD5 HMAC prevents the forgery of a new VTP message; the attacker is also unable to modify an existing VTP message. This HMAC exists on versions 1, 2, and 3 of VTP.
• Configuration Revision Number. A client only accepts a VLAN database that is more recent than its local copy. This prevents a replay attack where an attacker replays an old but valid VTP message. For antireplay to work, the HMAC authentication must be turned on to prevent an attacker from forging a new database version.
There were also a couple of vulnerabilities4 in the implementation of VTP in Cisco IOS that made a reload attack, and even potentially a buffer overflow attack, possible. The usual recommendation is to use a Cisco-recommended version for all of your switches. Because bugs can always happen, only enables VTP on trusted trunks.
Attack Tools
Yersinia states that it has attacks against VTP: adding and removing a VLAN as well as a DoS (probably by relying on old vulnerability). The authors verified the DoS attack but not the adding and removing of a VLAN.
Internetwork Routing Protocol Attack Suite5 (IRPAS) also has VTP attack tools. The existence of attack tools is proof that VTP protection must be implemented in a network that relies on VTP.
Continue reading here: Link Aggregation Protocols
Was this article helpful?
Readers' Questions
-
letterio1 year ago
- Reply