Cisco Ethernet switch Instrukcja Użytkownika Strona 72

  • Pobierz
  • Dodaj do moich podręczników
  • Drukuj
  • Strona
    / 84
  • Spis treści
  • BOOKMARKI
  • Oceniono. / 5. Na podstawie oceny klientów
Przeglądanie stron 71
727272
© 2002, Cisco Systems, Inc. All rights reserved.
l2-security-bh.ppt
Attacker
Mac:A IP:1
Victim
Mac:B IP:2
Promiscuous Port
Isolated Port
Private VLAN Attacks 2/2
¥ Only allows unidirectional traffic (Victim will ARP for A and fail)
¥ If both hosts were compromised, setting static ARP entries for each
other via the router will allow bi-directional traffic
¥ Most firewalls will not forward the packet like a router
¥ Note: this is not a PVLAN vulnerability as it enforced the rules!
S:A1 D:
C
2
PVLANs Work
Forward Packet
S:A1 D:C2
Routers Route:
Forward Packet
S:A1 D:B2
S:A1 D:
B
2
Intended PVLAN Security Is Bypassed
Router
Mac:C IP:3
Przeglądanie stron 71
1 2 ... 67 68 69 70 71 72 73 74 75 76 77 ... 83 84

Komentarze do niniejszej Instrukcji

Brak uwag