Layer 2 Attacks and Mitigation Techniques for the Cisco Catalyst 6500 Series Switches Running Cisco IOS Software
Kevin Lauerman, Jeff King · 2010
Security is at the forefront of most networks and many companies implement a comprehensive security policy encompassing many of the OSI layers, from application layer all the way down to IP security. However, one area that is often left untouched is hardening layer 2 and this can open the network to a variety of attacks and compromises. This document has a focus on understanding and preventing Layer 2 attacks on the Cisco® Catalyst® 6500 switching platform. Denial-of-Service (DoS) attacks are always a major concern as they can come from both internal and external sources. The focal point of this white paper is to understand how a DHCP Consumption Attack (DoS Attack) works and what techniques can be used on the Cisco Catalyst 6500 switch running Cisco IOS Software to mitigate this type of attack. An attack tool called Yersina was used to invoke this attack. A MacBook Pro laptop running VMware and Ubuntu (a Linux-based operating system) was used in the test. Note that the attack performed in this document was done in a controlled lab environment. We do not recommend that you perform this attack on your enterprise network.