Chapter 100 Examples: Port Security Configuration; And Mac Move Limiting, On An Ex Series Switch - Juniper JUNOS OS 10.4 - FOR EX REV 1 Manual

For ex series ethernet switches
Table of Contents

Advertisement

CHAPTER 100
Examples: Port Security Configuration
Example: Configuring Port Security, with DHCP Snooping, DAI, MAC Limiting, and MAC
Move Limiting, on an EX Series Switch
Copyright © 2010, Juniper Networks, Inc.
Example: Configuring Port Security, with DHCP Snooping, DAI, MAC Limiting, and MAC
Move Limiting, on an EX Series Switch on page 3073
Example: Configuring MAC Limiting, Including Dynamic and Allowed MAC Addresses,
to Protect the Switch from Ethernet Switching Table Overflow Attacks on page 3080
Example: Configuring a DHCP Server Interface as Untrusted to Protect the Switch from
Rogue DHCP Server Attacks on page 3083
Example: Configuring MAC Limiting to Protect the Switch from DHCP Starvation
Attacks on page 3087
Example: Configuring DHCP Snooping and DAI to Protect the Switch from ARP Spoofing
Attacks on page 3090
Example: Configuring Allowed MAC Addresses to Protect the Switch from DHCP
Snooping Database Alteration Attacks on page 3094
Example: Configuring DHCP Snooping, DAI , and MAC Limiting on an EX Series Switch
with Access to a DHCP Server Through a Second Switch on page 3097
Example: Configuring IP Source Guard with Other EX Series Switch Features to Mitigate
Address-Spoofing Attacks on Untrusted Access Interfaces on page 3104
Example: Configuring IP Source Guard on a Data VLAN That Shares an Interface with
a Voice VLAN on page 3112
Example: Setting Up DHCP Option 82 with an EX Series Switch as Relay Agent Between
Clients and a DHCP Server on page 3119
Example: Setting Up DHCP Option 82 on an EX Series Switch with No Relay Agent
Between Clients and DHCP Server on page 3122
Example: Configuring Proxy ARP on an EX Series Switch on page 3125
You can configure DHCP snooping, dynamic ARP inspection (DAI), MAC limiting, and
MAC move limiting on the access ports of EX Series switches to protect the switch and
the Ethernet LAN against address spoofing and Layer 2 denial-of-service (DoS) attacks.
You can also configure a trusted DHCP server and specific (allowed) MAC addresses for
the switch interfaces.
3073

Advertisement

Table of Contents
loading

This manual is also suitable for:

Junos os 10.4

Table of Contents