Get the App
SLTechnology News&Howtos  ›  Network Security  › 

Prevention of "ip deception"

Shulou Source: shulou.com Published: 2022-06-01 07:35:44 10月01日 Update

one.

To prevent mac address spoofing, Port Security can be enabled on the switch. Forging a mac address will cause the secure port to enter the errordisable state.

two.

Prevent ip address spoofing by enabling "dhcp snooping" globally on the switch

The main purpose of Ip spoofing is to forge the source address of the ip packet. After the packet sent back from the destination address enters the network segment where the forged ip is located, the router will re-encapsulate the data frame, at this time, it must know the correspondence of the ip-mac address, and "dhcp snooping" ensures the correct correspondence of the ip-mac address, so the response packet will be returned to the real terminal.

At this time, the * * end (the infected side) will send data, but there is no response data.

When the virus spreads, the * * end can be found accordingly.

On the * * side, no data was sent, but continued to receive responses.

When the virus spreads, you can temporarily add deny rules to the host firewall, or add deny-acl statements to the switch port to prevent it from being ddos***.

Tags: Address data port security time virus transmission continuous host switch global location accordingly status destination terminal network segment rules statements routing Apple Docker Huawei Linux macOS MariaDB Microsoft MySQL NVidia OPPO Reno vpn Shulou Information Apple macOS Docker