Switch Port Protection Flashcards
1
Q
Loop protection
A
Loop protection
• Connect two switches to each other
• They’ll send traffic back and forth forever
• There’s no “counting” mechanism at the MAC layer
• Connect two switches to each other
• They’ll send traffic back and forth forever
• There’s no “counting” mechanism at the MAC layer
2
Q
BPDU guard
A
BPDU guard • Spanning tree takes time to determine if a switch port should forward frames • Bypass the listening and learning states • Cisco calls this PortFast
3
Q
Root guard
A
Root guard
• Spanning tree determines the root bridge
• You can set the root bridge priority to 0, but that
doesn’t always guarantee the root
4
Q
Flood guard
A
Flood guard • Configure a maximum number of source MAC addresses on an interface • You decide how many is too many • You can also configure specific MAC addresses
5
Q
DHCP snooping
A
DHCP snooping
• IP tracking on a layer 2 device (switch)
• The switch is a DHCP firewall
• Trusted: Routers, switches, DHCP servers
• Untrusted: Other computers, unofficial DHCP servers