Загрузка...

DHCP Snooping + Dynamic ARP Inspection Lab — CCNA 200-301 | Cisco Packet Tracer

Practice this free, no login: https://packetmentor.com/topics/dynamic-arp-inspection/

ARP has no authentication — so any host can claim to be your gateway and quietly man-in-the-middle the network. We stop it the Cisco way: DHCP snooping builds a trusted MAC↔IP binding table, then Dynamic ARP Inspection uses it to drop forged ARP replies. Configure it, launch the attack, watch DAI kill it.

Full written guide: https://packetmentor.com/blog/layer-2-security-explained/

⏱️ Chapters
0:00 Demonstrating the ARP Man-in-the-Middle (MITM) attack.
2:54 Understanding the lab layout and switch roles.
4:02 Setting Trust boundaries (Preventing the #1 common mistake).
4:50 Access port and Vlan configurations on switch - A quick recap
6:04 Verificaiton of base configurations
6:40 The attacker (Illegitimate DHCP Server)
9:04 DHCP snooping — the binding table
10:18 Setting Trust boundaries (Preventing the #1 common mistake).
10:59 Ensuring the binding table is populated correctly.
12:00 Why DHCP snooping alone isn't enough (The attack persists).
13:50 Enabling Dynamic ARP Inspection to drop forged traffic.
15:12 Handling static IPs using ARP Access Control Lists (ACLs).
16:19 Testing, monitoring, and validating the security policy.

More free labs & simulators: https://packetmentor.com/practice/

Видео DHCP Snooping + Dynamic ARP Inspection Lab — CCNA 200-301 | Cisco Packet Tracer канала PacketMentor
Яндекс.Метрика
Все заметки Новая заметка Страницу в заметки
Страницу в закладки Мои закладки
На информационно-развлекательном портале SALDA.WS применяются cookie-файлы. Нажимая кнопку Принять, вы подтверждаете свое согласие на их использование.
О CookiesНапомнить позжеПринять