Free content for your website or blog
Home About Us Article Writing Most Read Articles Authors Blog Wiki Contact Us
RSS Register Login
Topics
 
Home > Computer Hardware >

CCNP Certification BCMSN Exam Tutorial: MAC Address Flooding

Date Published: 12th May 2007
Bookmark and Share Republish CCNP Certification BCMSN Exam Tutorial:  MAC Address Flooding
Author: Chris Bryant RSS Views: N/A PRINT ASK ABOUT THIS ARTICLE
Network attacks take many forms, and it's important to know how the potential security issues with ARP, DHCP, and MAC addresses. They're innocent looking enough, but each of these common network protocols and addresses can be turned against us. Today, we'll talk about what MAC Address Flooding is, how it can be used against our network, and the best defense against this attack.

A MAC Address Flooding attack is an attempt by a network intruder to overwhelm the switch memory reserved for maintenance of the MAC address table. The intruder generates a large number of frames with different source MAC addresses - all of them invalid. As the switch's MAC address table capabilities are exhausted, valid entries cannot be made - and this results in those valid frames being broadcast instead of unicast.


This has two side effects, both unpleasant:

As mentioned, the MAC address table fills to capacity, preventing legitimate entries from being made.

The large number of unnecessary frame flooding quickly consumes bandwidth as well as overall switch resources.


The best defense against MAC Address Flooding is a good offense, and in this case, that offense consists of port-based authentication and port security. By making sure our host devices are indeed who we think they are and authenticating them before they join our network, we reduce the potential for an intruder to unleash a MAC Address Flooding attack on our network. The key isn't to fight the intruder once they're in our network - the key is to keep them out in the first place!

This article is free for republishing
Source: http://www.articlealley.com/article_159074_10.html
About the Author
Chris Bryant, CCIE #12933, is the owner of The Bryant Advantage, home of over 100 free certification exam tutorials, including Cisco CCNA certification test prep articles. His exclusive Cisco CCNA study guide and Cisco CCNA training is also available! Visit his blog and sign up for Cisco Certification Central, a daily newsletter packed with CCNA, Network+, Security+, A+, and CCNP certification exam practice questions! A free 7-part course, “How To Pass The CCNA”, is also available, and you can attend an in-person or online CCNA boot camp with The Bryant Advantage!
Bookmark and Share Republish CCNP Certification BCMSN Exam Tutorial:  MAC Address Flooding

Ask a Question About this Article

>> Non availability of birth certificate
>> Shepards Chapel.com When was the great flood. I am ...
>> Lost graduation certificate & need cc: for Geico
>> CLT-HEW needs certification verifing contact # or website address.
Powered by