Security Overview

Network Security Features

Feature

Default

Security Guidelines

More Information and

 

Setting

 

Configuration Details

 

 

 

 

Connection-

none

This feature helps protect the network from attack and

Chapter 3, “Virus Throttling

Rate Filtering

 

is recommended for use on the network edge. It is

(Connection-Rate Filtering)”

based on

 

primarily focused on the class of worm-like malicious

 

Virus-Throttling

 

code that tries to replicate itself by taking advantage of

 

Technology

 

weaknesses in network applications behind unsecured

 

 

 

ports. In this case, the malicious code tries to create a

 

 

 

large number of outbound connections on an interface

 

 

 

in a short time. Connection-Rate filtering detects hosts

 

 

 

that are generating traffic that exhibits this behavior, and

 

 

 

causes the switch to generate warning messages and

 

 

 

(optionally) to throttle or drop all traffic from the

 

 

 

offending hosts.

 

ICMP

none

This feature helps defeat ICMP denial-of-service

Rate-Limiting

 

attacks by restricting ICMP traffic to percentage levels

 

 

that permit necessary ICMP functions, but throttle

 

 

additional traffic that may be due to worms or viruses

 

 

(reducing their spread and effect).

Management and Configuration Guide, in the chapter on “Port Traffic Controls” refer to the section “ICMP Rate-Limiting”

Spanning Tree

none

These features prevent your switch from malicious

Protection

 

attacks or configuration errors:

 

 

BPDU Filtering and BPDU Protection: Protects the

 

 

network from denial-of-service attacks that use

 

 

spoofing BPDUs by dropping incoming BPDU frames

 

 

and/or blocking traffic through a port.

 

 

STP Root Guard: Protects the STP root bridge from

 

 

malicious attacks or configuration mistakes.

Advanced Traffic Management Guide, refer to the chapter “Multiple Instance Spanning-Tree Operation”

DHCP Snooping, none

Dynamic ARP

Protection, and Dynamic IP Lockdown

These features provide the following additional protections for your network:

DHCP Snooping: Protects your network from common DHCP attacks, such as address spoofing and repeated address requests.

Dynamic ARP Protection: Protects your network from ARP cache poisoning.

Dynamic IP Lockdown: Prevents IP source address spoofing on a per-port and per-VLAN basis

Instrumentation Monitor. Helps identify a variety of malicious attacks by generating alerts for detected anomalies on the switch.

Chapter 11, “Configuring

Advanced Threat

Protection”

1-8