[AQ] Switch principle/MACOF

Source: Internet
Author: User
How the Switch works
  • Simply put, it is based on the source Mac learning-form cam table, which is forwarded according to the Cam table. Normally ARP broadcasts first, SW receives all exits after sending to this VLAN, all machine learns to update ARP cache. The target machine returns the unicast ARP reply to this machine. Then transfer the data (unicast). Also to a certain extent, to avoid the flow of the Hu channeling, to ensure the safety.

The SW port Forwarding (security) also relies on the switching fabric
Reference

The life of the cam table for each entry defaults to 5min.

Implementing Cisco IP switched Networks (SWITCH) Foundation learning guide:network Design Fundamentals

  • The key is that the cam table has a limited capacity.

  • If the cam table of the switch is fully learned and the unicast packet is received, it is emitted from all interfaces , which deviates from the security of the switch port
MACOF Tool Forged Source mac+ IP, a large number of IP packets.

Fills the cam table with the switch, causing the switch to broadcast the unknown unicast packet. Loss of security.

Reference: Mac flooding: Capturing unknown unicast traffic: analyzing FTP passwords

Resolution Policy:
Limit the number of MAC addresses that can be learned at each port of SW (open port security)

The DHCP anti-exhaustion attack is also used by this policy defense.

[AQ] Switch principle/MACOF

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.