EasyManuals Logo

Cisco SG350-10MP Administration Guide

Cisco SG350-10MP
762 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #503 background imageLoading...
Page #503 background image
Security
ARP Inspection
360 Cisco 350, 350X and 550X Series Managed Switches, Firmware Release 2.4, ver 0.4
17
The following shows an example of ARP cache poisoning.
ARP Cache Poisoning
Hosts A, B, and C are connected to the switch on interfaces A, B and C, all of which are on the
same subnet. Their IP, MAC addresses are shown in parentheses; for example, Host A uses IP
address IA and MAC address MA. When Host A needs to communicate with Host B at the IP
layer, it broadcasts an ARP request for the MAC address associated with IP address IB. Host B
responds with an ARP reply. The switch and Host A update their ARP cache with the MAC
and IP of Host B.
Host C can poison the ARP caches of the switch, Host A, and Host B by broadcasting forged
ARP responses with bindings for a host with an IP address of IA (or IB) and a MAC address of
MC. Hosts with poisoned ARP caches use the MAC address MC as the destination MAC
address for traffic intended for IA or IB, which enables Host C intercepts that traffic. Because
Host C knows the true MAC addresses associated with IA and IB, it can forward the
intercepted traffic to those hosts by using the correct MAC address as the destination. Host C
has inserted itself into the traffic stream from Host A to Host B, the classic man-in-the-middle
attack.
This section describes ARP Inspection and covers the following topics:
How ARP Prevents Cache Poisoning
Interaction Between ARP Inspection and DHCP Snooping
•ARP Defaults
ARP Inspection Work Flow

Table of Contents

Other manuals for Cisco SG350-10MP

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the Cisco SG350-10MP and is the answer not in the manual?

Cisco SG350-10MP Specifications

General IconGeneral
ModelSG350-10MP
CategorySwitch
PoE Budget130W
Switching Capacity20 Gbps
Forwarding Rate14.88 Mpps
Power SupplyInternal
Ports8 x 10/100/1000 PoE+ + 2 x Gigabit SFP
MAC Address Table Size16K
Jumbo Frame Support9216 bytes
ManagementWeb-based, CLI, SNMP
Operating Temperature0°C to 45°C (32°F to 113°F)
Storage Temperature-20°C to 70°C (-4°F to 158°F)
Operating Humidity10% to 90% relative humidity, non-condensing
Storage Humidity5% to 95% relative humidity, non-condensing
Dimensions (W x D x H)279.4 x 170 x 44 mm (11.0 x 6.7 x 1.73 in)

Related product manuals