Chapter 94 Examples: Port Security Configuration; And Mac Move Limiting, On An Ex Series Switch - Juniper JUNOS OS 10.3 - SOFTWARE Manual

For ex series ethernet switches
Hide thumbs Also See for JUNOS OS 10.3 - SOFTWARE:
Table of Contents

Advertisement

CHAPTER 94
Examples: Port Security Configuration
Example: Configuring Port Security, with DHCP Snooping, DAI, MAC Limiting, and MAC
Move Limiting, on an EX Series Switch
Copyright © 2010, Juniper Networks, Inc.
Example: Configuring Port Security, with DHCP Snooping, DAI, MAC Limiting, and MAC
Move Limiting, on an EX Series Switch on page 2849
Example: Configuring MAC Limiting, Including Dynamic and Allowed MAC Addresses,
to Protect the Switch from Ethernet Switching Table Overflow Attacks on page 2856
Example: Configuring a DHCP Server Interface as Untrusted to Protect the Switch from
Rogue DHCP Server Attacks on page 2859
Example: Configuring MAC Limiting to Protect the Switch from DHCP Starvation
Attacks on page 2863
Example: Configuring DHCP Snooping and DAI to Protect the Switch from ARP Spoofing
Attacks on page 2866
Example: Configuring Allowed MAC Addresses to Protect the Switch from DHCP
Snooping Database Alteration Attacks on page 2870
Example: Configuring DHCP Snooping, DAI , and MAC Limiting on an EX Series Switch
with Access to a DHCP Server Through a Second Switch on page 2873
Example: Configuring IP Source Guard with Other EX Series Switch Features to Mitigate
Address-Spoofing Attacks on Untrusted Access Interfaces on page 2880
Example: Configuring IP Source Guard on a Data VLAN That Shares an Interface with
a Voice VLAN on page 2888
Example: Setting Up DHCP Option 82 with an EX Series Switch as Relay Agent Between
Clients and a DHCP Server on page 2895
Example: Setting Up DHCP Option 82 on an EX Series Switch with No Relay Agent
Between Clients and DHCP Server on page 2898
Example: Configuring Proxy ARP on an EX Series Switch on page 2901
You can configure DHCP snooping, dynamic ARP inspection (DAI), MAC limiting, and
MAC move limiting on the access ports of EX Series switches to protect the switch and
the Ethernet LAN against address spoofing and Layer 2 denial-of-service (DoS) attacks.
You can also configure a trusted DHCP server and specific (allowed) MAC addresses for
the switch interfaces.
2849

Advertisement

Table of Contents
loading

Table of Contents