רוב המתקפות על מתחילות ברשת: מישהו מתחבר לשקע פנוי, מקים Rogue DHCP או מריץ הרעלת . הגנות שכבה 2 ו־3 עוצרות את זה מוקדם.
- — מגביל כמה כתובות MAC מותרות בפורט.
- — רק פורטים מוגדרים (Trusted) רשאים לענות כ־DHCP.
- Dynamic ARP Inspection — מונע הרעלת ARP (MitM).
- — אימות המכשיר/משתמש מול (NPS) לפני קבלת גישה לרשת.
- ACL — סינון תעבורה לפי כתובת ופורט.
! Port Security
Switch(config-if)# switchport port-security
Switch(config-if)# switchport port-security maximum 2
Switch(config-if)# switchport port-security violation restrict
Switch(config-if)# switchport port-security mac-address sticky
! DHCP Snooping
Switch(config)# ip dhcp snooping
Switch(config)# ip dhcp snooping vlan 10,20
Switch(config-if)# ip dhcp snooping trust
! ACL מורחב — חסימת SMB מרשת אורחים אל חוות השרתים
Router(config)# ip access-list extended GUEST-IN
Router(config-ext-nacl)# deny tcp 192.168.99.0 0.0.0.255 192.168.50.0 0.0.0.255 eq 445
Router(config-ext-nacl)# permit ip any any
Router(config-if)# ip access-group GUEST-IN inbashארכיטקטורה ותיאוריה — מתחת למכסה המנוע
אבטחת L2 היא קו ההגנה הראשון: אם התוקף כבר בתוך המתג, ACL בנתב לא יעזור. , ו־Dynamic ARP Inspection סוגרים את רוב מתקפות הרשת המקומית.
- הפרש בין מצבי ההפרה: protect זורק בשקט, restrict זורק + מונה + SNMP trap, shutdown מעביר את הפורט ל־err-disabled עד התערבות ידנית או errdisable recovery.
- : מסמן פורטים כ־Trusted (לכיוון שרת DHCP חוקי) ו־Untrusted (משתמשים) — חוסם Rogue DHCP.
- : בודק ARP מול טבלת ה־Snooping — עוצר ARP Spoofing.
- : אימות המשתמש/המחשב מול /NPS לפני שהפורט בכלל נפתח.
הגדרה מעשית (CLI)
! Port Security
SW(config-if)# switchport mode access
SW(config-if)# switchport port-security
SW(config-if)# switchport port-security maximum 2
SW(config-if)# switchport port-security mac-address sticky
SW(config-if)# switchport port-security violation restrict
! DHCP Snooping + DAI
SW(config)# ip dhcp snooping
SW(config)# ip dhcp snooping vlan 10,20
SW(config)# interface gi0/24
SW(config-if)# ip dhcp snooping trust
SW(config)# ip arp inspection vlan 10,20
! 802.1X
SW(config)# aaa new-model
SW(config)# aaa authentication dot1x default group radius
SW(config)# radius server NPS
SW(config-radius-server)# address ipv4 192.168.10.10 auth-port 1812
SW(config-radius-server)# key S3cret!
SW(config)# dot1x system-auth-control
SW(config-if)# authentication port-control auto
SW(config-if)# dot1x pae authenticatorbashתרחישי אמת בארגון
- חדרי ישיבות ולובי: + Guest VLAN כדי שאורח לא יתחבר לרשת הפנימית.
- בארגון עם : NPS מאמת את חשבון המחשב, ולפי הקבוצה מקצה VLAN דינמי.
- מונע נזק מ־Router ביתי שעובד מביא ומחבר לרשת.
אבחון ופתרון תקלות
SW# show port-security interface gi0/5
SW# show port-security address
SW# show ip dhcp snooping binding
SW# show ip arp inspection statistics
SW# show authentication sessions interface gi0/5
SW# show interfaces status err-disabled
SW(config-if)# shutdown
SW(config-if)# no shutdown ! שחרור פורט err-disabledbash- פורט נכנס ל־err-disabled אחרי החלפת מחשב → מוחקים את ה־sticky MAC הישן.
- טלפון IP + מחשב על אותו פורט צריכים maximum 2 לפחות.
- נכשל → בדוק תעודה/סיסמה, קישוריות ל־ ומדיניות ב־NPS.
מילון מונחים ושורת פקודות מהירה
- violation: protect (זורק), restrict (זורק+לוג), shutdown (ברירת מחדל, err-disabled)
- errdisable recovery cause psecure-violation — שחזור אוטומטי
- Snooping trust = רק לכיוון שרת DHCP חוקי
- = Supplicant + Authenticator (Switch) + Authentication Server (/NPS)