Most attacks on start on the network: someone connects to an available port, sets up a Rogue DHCP, or runs poisoning. Layer 2 and 3 protections stop this early.
- — Limits how many MAC addresses are allowed on a port.
- — Only defined (Trusted) ports are allowed to respond as DHCP.
- Dynamic ARP Inspection — Prevents ARP poisoning (MitM).
- — Authenticates the device/user against (NPS) before granting network access.
- ACL — Filters traffic by address and port.
! Port Security
Switch(config-if)# switchport port-security
Switch(config-if)# switchport port-security maximum 2
Switch(config-if)# switchport port-security violation restrict
Switch(config-if)# switchport port-security mac-address sticky
! DHCP Snooping
Switch(config)# ip dhcp snooping
Switch(config)# ip dhcp snooping vlan 10,20
Switch(config-if)# ip dhcp snooping trust
! Extended ACL — Block SMB from Guest Network to Server Farm
Router(config)# ip access-list extended GUEST-IN
Router(config-ext-nacl)# deny tcp 192.168.99.0 0.0.0.255 192.168.50.0 0.0.0.255 eq 445
Router(config-ext-nacl)# permit ip any any
Router(config-if)# ip access-group GUEST-IN inbashArchitecture and Theory — Under the Hood
L2 security is the first line of defense: if the attacker is already inside the switch, an ACL on the router won't help. , , and Dynamic ARP Inspection stop most local network attacks.
- Difference between violation modes: protect silently drops, restrict drops + counts + SNMP trap, shutdown moves the port to err-disabled until manual intervention or errdisable recovery.
- : Marks ports as Trusted (towards a legitimate DHCP server) and Untrusted (users) — blocks Rogue DHCP.
- : Checks ARP against the Snooping table — stops ARP Spoofing.
- : Authenticates the user/computer against /NPS before the port is even opened.
Practical Configuration (CLI)
! Port Security
SW(config-if)# switchport mode access
SW(config-if)# switchport port-security
SW(config-if)# switchport port-security maximum 2
SW(config-if)# switchport port-security mac-address sticky
SW(config-if)# switchport port-security violation restrict
! DHCP Snooping + DAI
SW(config)# ip dhcp snooping
SW(config)# ip dhcp snooping vlan 10,20
SW(config)# interface gi0/24
SW(config-if)# ip dhcp snooping trust
SW(config)# ip arp inspection vlan 10,20
! 802.1X
SW(config)# aaa new-model
SW(config)# aaa authentication dot1x default group radius
SW(config)# radius server NPS
SW(config-radius-server)# address ipv4 192.168.10.10 auth-port 1812
SW(config-radius-server)# key S3cret!
SW(config)# dot1x system-auth-control
SW(config-if)# authentication port-control auto
SW(config-if)# dot1x pae authenticatorbashReal-world Scenarios in an Organization
- Meeting rooms and lobby: + Guest VLAN so a guest cannot connect to the internal network.
- in an organization with : NPS authenticates the computer account, and assigns a dynamic VLAN based on the group.
- prevents damage from a home Router that someone brings and connects to the network.
Troubleshooting
SW# show port-security interface gi0/5
SW# show port-security address
SW# show ip dhcp snooping binding
SW# show ip arp inspection statistics
SW# show authentication sessions interface gi0/5
SW# show interfaces status err-disabled
SW(config-if)# shutdown
SW(config-if)# no shutdown ! Release err-disabled portbash- Port enters err-disabled after replacing a computer → Delete the old sticky MAC.
- IP phone + computer on the same port need a maximum of 2 at least.
- fails → Check certificate/password, connectivity to , and policy in NPS.
Glossary and Quick Command Line
- violation: protect (drops), restrict (drops+logs), shutdown (default, err-disabled)
- errdisable recovery cause psecure-violation — automatic recovery
- Snooping trust = only towards a legitimate DHCP server
- = Supplicant + Authenticator (Switch) + Authentication Server (/NPS)