You are on page 1of 44

K THUT TN CNG V

PHNG TH TRONG
MNG LAN
2012 Cisco and/or its affiliates. All rights reserved. 1
MNG LAN
MNG NGY NAY
CNG C vs K NNG
NI DUNG
Khi nimv s nh hng ca Sniffing trong
mng doanh nghip
Hot ng ca Sniifing
Cc phng thc tn cng da trn Sniifing Cc phng thc tn cng da trn Sniifing
MAC Flooding Attack
DEMO
Question & Answer Question & Answer
Phng thc tn cng
Tn cng t chi dch v DHCP
Tn cng gi mo DHCP Server
ARP Poisoning
Configuring DAI
DEMO
Question & Answer Question & Answer
Catalyst Integrated Security
Configuration
sw(config)# ip dhcp snooping
sw(config)# ip dhcp snooping vlan 10,20
sw(config)# ip arp inspection vlan 10,20
sw(config)# interface fastethernet 0/1
sw(config-if)# description Access Port
sw(config-if)# switchport mode access
sw(config-if)# switchport access vlan 10
sw(config-if)# switchport port-security maximum 2 sw(config-if)# switchport port-security maximum 2
sw(config-if)# switchport port-security violation restrict
sw(config-if)# switchport port-security
sw(config-if)# ip dhcp limit rate 50
sw(config-if)# ip verify source port-security
sw(config)# interface fastethernet 0/24
sw(config-if)# description Uplink
sw(config-if)# switchport mode trunk
sw(config-if)# switchport trunk allowed vlan 10,20
sw(config-if)# ip dhcp snooping trust
sw(config-if)# ip arp inspection trust
Etherflood
Question & Answer
Tng kt
Gimthiu nguy c tn cng sniffer trong
mng lan ca doanh nghip chng ta nn kt
hp 1 s phng thc :
Port Security Port Security
Dynamic ARP Inspection
IP Source guard
Hn ch truy cp, xc thc bng AAA, m ha
thng tin

You might also like