Port Security For Ex Series Switches Overview; Port Security Overview - Juniper JUNOS OS 10.3 - SOFTWARE Manual

For ex series ethernet switches
Hide thumbs Also See for JUNOS OS 10.3 - SOFTWARE:
Table of Contents

Advertisement

CHAPTER 93

Port Security Overview

Port Security for EX Series Switches Overview

Copyright © 2010, Juniper Networks, Inc.
Port Security for EX Series Switches Overview on page 2825
Understanding How to Protect Access Ports on EX Series Switches from Common
Attacks on page 2826
Understanding DHCP Snooping for Port Security on EX Series Switches on page 2829
Understanding DAI for Port Security on EX Series Switches on page 2836
Understanding MAC Limiting and MAC Move Limiting for Port Security on EX Series
Switches on page 2838
Understanding Trusted DHCP Servers for Port Security on EX Series Switches on page 2840
Understanding DHCP Option 82 for Port Security on EX Series Switches on page 2840
Understanding IP Source Guard for Port Security on EX Series Switches on page 2843
Understanding Proxy ARP on EX Series Switches on page 2846
Ethernet LANs are vulnerable to attacks such as address spoofing (forging) and Layer 2
denial of service (DoS) on network devices. Port security features help protect the access
ports on your switch against the losses of information and productivity that can result
from such attacks.
Juniper Networks Junos operating system (Junos OS) on Juniper Networks EX Series
Ethernet Switches provides features to help secure ports on the switch. The ports can
be categorized as either trusted or untrusted. You apply policies appropriate to those
categories to protect against various types of attacks.
Port security features can be turned on to obtain the most robust port security level.
Basic port security features are enabled in the switch's default configuration. You can
configure additional features with minimal configuration steps.
Port security features on EX Series switches are:
DHCP snooping—Filters and blocks ingress DHCP server messages on untrusted ports;
builds and maintains an IP-address/MAC-address binding database (called the DHCP
snooping database). You enable this feature on VLANs.
Dynamic ARP inspection (DAI)—Prevents ARP spoofing attacks. ARP requests and
replies are compared against entries in the DHCP snooping database, and filtering
2825

Advertisement

Table of Contents
loading

Table of Contents