דילוג לתוכן הראשי
AD Academy
CCNA — יסודות רשתות Cisco
מתחילים13 דקותעודכן לאחרונה: נושא 6 מתוך 12

אבטחת רשת ב־CCNA: Port Security, ACL ו־802.1X

הגנות בסיסיות במתג ובנתב, ולמה הן חשובות גם ל־Active Directory.

לא הושלם

מה תלמדו כאן

  • איך Port Security מגביל חיבורים במתג
  • מה ACL עושה בנתב
  • איך 802.1X מתחבר ל־AD

כדאי לקרוא לפני הנושא הזה:שירותי רשת: DHCP, DNS, NAT ו־NTP

רוב המתקפות על מתחילות ברשת: מישהו מתחבר לשקע פנוי, מקים Rogue DHCP או מריץ הרעלת . הגנות שכבה 2 ו־3 עוצרות את זה מוקדם.

  • — מגביל כמה כתובות MAC מותרות בפורט.
  • — רק פורטים מוגדרים (Trusted) רשאים לענות כ־DHCP.
  • Dynamic ARP Inspection — מונע הרעלת ARP (MitM).
  • — אימות המכשיר/משתמש מול (NPS) לפני קבלת גישה לרשת.
  • ACL — סינון תעבורה לפי כתובת ופורט.
! Port Security
Switch(config-if)# switchport port-security
Switch(config-if)# switchport port-security maximum 2
Switch(config-if)# switchport port-security violation restrict
Switch(config-if)# switchport port-security mac-address sticky

! DHCP Snooping
Switch(config)# ip dhcp snooping
Switch(config)# ip dhcp snooping vlan 10,20
Switch(config-if)# ip dhcp snooping trust

! ACL מורחב — חסימת SMB מרשת אורחים אל חוות השרתים
Router(config)# ip access-list extended GUEST-IN
Router(config-ext-nacl)# deny tcp 192.168.99.0 0.0.0.255 192.168.50.0 0.0.0.255 eq 445
Router(config-ext-nacl)# permit ip any any
Router(config-if)# ip access-group GUEST-IN in
bash
ארכיטקטורה ותיאוריה — מתחת למכסה המנוע

אבטחת L2 היא קו ההגנה הראשון: אם התוקף כבר בתוך המתג, ACL בנתב לא יעזור. , ו־Dynamic ARP Inspection סוגרים את רוב מתקפות הרשת המקומית.

  • הפרש בין מצבי ההפרה: protect זורק בשקט, restrict זורק + מונה + SNMP trap, shutdown מעביר את הפורט ל־err-disabled עד התערבות ידנית או errdisable recovery.
  • : מסמן פורטים כ־Trusted (לכיוון שרת DHCP חוקי) ו־Untrusted (משתמשים) — חוסם Rogue DHCP.
  • : בודק ARP מול טבלת ה־Snooping — עוצר ARP Spoofing.
  • : אימות המשתמש/המחשב מול /NPS לפני שהפורט בכלל נפתח.
הגדרה מעשית (CLI)
! Port Security
SW(config-if)# switchport mode access
SW(config-if)# switchport port-security
SW(config-if)# switchport port-security maximum 2
SW(config-if)# switchport port-security mac-address sticky
SW(config-if)# switchport port-security violation restrict

! DHCP Snooping + DAI
SW(config)# ip dhcp snooping
SW(config)# ip dhcp snooping vlan 10,20
SW(config)# interface gi0/24
SW(config-if)# ip dhcp snooping trust
SW(config)# ip arp inspection vlan 10,20

! 802.1X
SW(config)# aaa new-model
SW(config)# aaa authentication dot1x default group radius
SW(config)# radius server NPS
SW(config-radius-server)# address ipv4 192.168.10.10 auth-port 1812
SW(config-radius-server)# key S3cret!
SW(config)# dot1x system-auth-control
SW(config-if)# authentication port-control auto
SW(config-if)# dot1x pae authenticator
bash
תרחישי אמת בארגון
  • חדרי ישיבות ולובי: + Guest VLAN כדי שאורח לא יתחבר לרשת הפנימית.
  • בארגון עם : NPS מאמת את חשבון המחשב, ולפי הקבוצה מקצה VLAN דינמי.
  • מונע נזק מ־Router ביתי שעובד מביא ומחבר לרשת.
אבחון ופתרון תקלות
SW# show port-security interface gi0/5
SW# show port-security address
SW# show ip dhcp snooping binding
SW# show ip arp inspection statistics
SW# show authentication sessions interface gi0/5
SW# show interfaces status err-disabled
SW(config-if)# shutdown
SW(config-if)# no shutdown          ! שחרור פורט err-disabled
bash
  • פורט נכנס ל־err-disabled אחרי החלפת מחשב → מוחקים את ה־sticky MAC הישן.
  • טלפון IP + מחשב על אותו פורט צריכים maximum 2 לפחות.
  • נכשל → בדוק תעודה/סיסמה, קישוריות ל־ ומדיניות ב־NPS.
מילון מונחים ושורת פקודות מהירה
  • violation: protect (זורק), restrict (זורק+לוג), shutdown (ברירת מחדל, err-disabled)
  • errdisable recovery cause psecure-violation — שחזור אוטומטי
  • Snooping trust = רק לכיוון שרת DHCP חוקי
  • = Supplicant + Authenticator (Switch) + Authentication Server (/NPS)

בדוק את עצמך

איזו הגנה עוצרת שרת DHCP מזויף ברשת?

מה מספק 802.1X?

העמוד הזה עזר לך?