+ All Categories
Home > Technology > Seminariode Seguridad L2

Seminariode Seguridad L2

Date post: 12-Jun-2015
Category:
Upload: christian-nieto
View: 1,166 times
Download: 0 times
Share this document with a friend
Popular Tags:
72
1 © 2005 Cisco Systems, Inc. All rights reserved. 0849_Icons_May2005 Cisco Public L2 Security Issues for small and medium enterprise Joffre Pesántez V. Ing. CCNA – CCDA – CCDP CCNP – Comp Tia Linux +
Transcript
Page 1: Seminariode Seguridad L2

1© 2005 Cisco Systems, Inc. All rights reserved.10849_Icons_May2005 Cisco Public

L2 Security Issues for small and medium enterprise

Joffre Pesántez V. Ing.

CCNA – CCDA – CCDP

CCNP – Comp Tia Linux +

Page 2: Seminariode Seguridad L2

2© 2005 Cisco Systems, Inc. All rights reserved. 10849_Icons_May2005 Cisco Public

AGENDA

• Ataques comunes en Capa 2

• Asegurando sus equipos de Capa 2

Page 3: Seminariode Seguridad L2

3© 2005 Cisco Systems, Inc. All rights reserved. 10849_Icons_May2005 Cisco Public

Ataques comunes en Capa 2

Page 4: Seminariode Seguridad L2

4© 2005 Cisco Systems, Inc. All rights reserved. 10849_Icons_May2005 Cisco Public

Ataques Comunes en Capa 2

• MAC Attacks (CAM Table Overflow)

• DHCP Attacks

• ARP Attacks

• Spoofing Attacks

• Power over Ethernet Attack

• VLAN hopping

• General Countermeasures

Page 5: Seminariode Seguridad L2

5© 2005 Cisco Systems, Inc. All rights reserved. 10849_Icons_May2005 Cisco Public

Mac Attacks

Page 6: Seminariode Seguridad L2

6© 2005 Cisco Systems, Inc. All rights reserved. 10849_Icons_May2005 Cisco Public

CAM Overview

Page 7: Seminariode Seguridad L2

7© 2005 Cisco Systems, Inc. All rights reserved. 10849_Icons_May2005 Cisco Public

Poblando la Tabla CAM (1)

Page 8: Seminariode Seguridad L2

8© 2005 Cisco Systems, Inc. All rights reserved. 10849_Icons_May2005 Cisco Public

Poblando la Tabla CAM (2)

Page 9: Seminariode Seguridad L2

9© 2005 Cisco Systems, Inc. All rights reserved. 10849_Icons_May2005 Cisco Public

Poblando la Tabla CAM (3)

Page 10: Seminariode Seguridad L2

10© 2005 Cisco Systems, Inc. All rights reserved. 10849_Icons_May2005 Cisco Public

CAM Overflow

Page 11: Seminariode Seguridad L2

11© 2005 Cisco Systems, Inc. All rights reserved. 10849_Icons_May2005 Cisco Public

CAM Overflow: Macof tool

Page 12: Seminariode Seguridad L2

12© 2005 Cisco Systems, Inc. All rights reserved. 10849_Icons_May2005 Cisco Public

CAM Overflow: Macof tool

Page 13: Seminariode Seguridad L2

13© 2005 Cisco Systems, Inc. All rights reserved. 10849_Icons_May2005 Cisco Public

Mac Flooding using macof

Page 14: Seminariode Seguridad L2

14© 2005 Cisco Systems, Inc. All rights reserved. 10849_Icons_May2005 Cisco Public

Mack Attack: Contramedidas

Page 15: Seminariode Seguridad L2

15© 2005 Cisco Systems, Inc. All rights reserved. 10849_Icons_May2005 Cisco Public

MAC Attack: Contramedidas

Page 16: Seminariode Seguridad L2

16© 2005 Cisco Systems, Inc. All rights reserved. 10849_Icons_May2005 Cisco Public

MAC Attack: Contramedidas

Page 17: Seminariode Seguridad L2

17© 2005 Cisco Systems, Inc. All rights reserved. 10849_Icons_May2005 Cisco Public

DHCP Attacks

Page 18: Seminariode Seguridad L2

18© 2005 Cisco Systems, Inc. All rights reserved. 10849_Icons_May2005 Cisco Public

DHCP Overview

Page 19: Seminariode Seguridad L2

19© 2005 Cisco Systems, Inc. All rights reserved. 10849_Icons_May2005 Cisco Public

DHCP Attack: Starvation

Page 20: Seminariode Seguridad L2

20© 2005 Cisco Systems, Inc. All rights reserved. 10849_Icons_May2005 Cisco Public

Countermeasures: Port Security

Page 21: Seminariode Seguridad L2

21© 2005 Cisco Systems, Inc. All rights reserved. 10849_Icons_May2005 Cisco Public

DHCP Attack: Rogue DHCP Server

Page 22: Seminariode Seguridad L2

22© 2005 Cisco Systems, Inc. All rights reserved. 10849_Icons_May2005 Cisco Public

Contramedida: VLAN access-list

Page 23: Seminariode Seguridad L2

23© 2005 Cisco Systems, Inc. All rights reserved. 10849_Icons_May2005 Cisco Public

Contramedida: DHCP Snooping

Page 24: Seminariode Seguridad L2

24© 2005 Cisco Systems, Inc. All rights reserved. 10849_Icons_May2005 Cisco Public

Contramedidas: DHCP Snooping

Page 25: Seminariode Seguridad L2

25© 2005 Cisco Systems, Inc. All rights reserved. 10849_Icons_May2005 Cisco Public

ARP Attacks

http://www.oxid.it/downloads/apr-intro.swf

Page 26: Seminariode Seguridad L2

26© 2005 Cisco Systems, Inc. All rights reserved. 10849_Icons_May2005 Cisco Public

ARP Attacks

Page 27: Seminariode Seguridad L2

27© 2005 Cisco Systems, Inc. All rights reserved. 10849_Icons_May2005 Cisco Public

Contramedidas: Dynamic ARP Inspection

Page 28: Seminariode Seguridad L2

28© 2005 Cisco Systems, Inc. All rights reserved. 10849_Icons_May2005 Cisco Public

Contramedidas: DAI

Page 29: Seminariode Seguridad L2

29© 2005 Cisco Systems, Inc. All rights reserved. 10849_Icons_May2005 Cisco Public

Contramedidas: DAI

Page 30: Seminariode Seguridad L2

30© 2005 Cisco Systems, Inc. All rights reserved. 10849_Icons_May2005 Cisco Public

Contramedidas: DAI

Page 31: Seminariode Seguridad L2

31© 2005 Cisco Systems, Inc. All rights reserved. 10849_Icons_May2005 Cisco Public

Contramedidas: DAI

Page 32: Seminariode Seguridad L2

32© 2005 Cisco Systems, Inc. All rights reserved. 10849_Icons_May2005 Cisco Public

Contramedidas: DAI

Page 33: Seminariode Seguridad L2

33© 2005 Cisco Systems, Inc. All rights reserved. 10849_Icons_May2005 Cisco Public

Spoofing Attack

Page 34: Seminariode Seguridad L2

34© 2005 Cisco Systems, Inc. All rights reserved. 10849_Icons_May2005 Cisco Public

Spoofing Attack

Page 35: Seminariode Seguridad L2

35© 2005 Cisco Systems, Inc. All rights reserved. 10849_Icons_May2005 Cisco Public

Contramedida: IP Source Guard

Page 36: Seminariode Seguridad L2

36© 2005 Cisco Systems, Inc. All rights reserved. 10849_Icons_May2005 Cisco Public

Contramedida: IP Source Guard

Page 37: Seminariode Seguridad L2

37© 2005 Cisco Systems, Inc. All rights reserved. 10849_Icons_May2005 Cisco Public

Contramedida: IP Source Guard

Page 38: Seminariode Seguridad L2

38© 2005 Cisco Systems, Inc. All rights reserved. 10849_Icons_May2005 Cisco Public

Sumario

Page 39: Seminariode Seguridad L2

39© 2005 Cisco Systems, Inc. All rights reserved. 10849_Icons_May2005 Cisco Public

Spanning Tree Attack

Page 40: Seminariode Seguridad L2

40© 2005 Cisco Systems, Inc. All rights reserved. 10849_Icons_May2005 Cisco Public

Spanning Tree Basics

Page 41: Seminariode Seguridad L2

41© 2005 Cisco Systems, Inc. All rights reserved. 10849_Icons_May2005 Cisco Public

Spanning Tree Attack

Page 42: Seminariode Seguridad L2

42© 2005 Cisco Systems, Inc. All rights reserved. 10849_Icons_May2005 Cisco Public

Spanning Tree Attack

Page 43: Seminariode Seguridad L2

43© 2005 Cisco Systems, Inc. All rights reserved. 10849_Icons_May2005 Cisco Public

Contramedidas: BPDU Guard

Page 44: Seminariode Seguridad L2

44© 2005 Cisco Systems, Inc. All rights reserved. 10849_Icons_May2005 Cisco Public

Contramedidas: Root Guard

Page 45: Seminariode Seguridad L2

45© 2005 Cisco Systems, Inc. All rights reserved. 10849_Icons_May2005 Cisco Public

CDP Attack

Page 46: Seminariode Seguridad L2

46© 2005 Cisco Systems, Inc. All rights reserved. 10849_Icons_May2005 Cisco Public

CDP Attack

Page 47: Seminariode Seguridad L2

47© 2005 Cisco Systems, Inc. All rights reserved. 10849_Icons_May2005 Cisco Public

MATRIZ DE EQUIPOS

Page 48: Seminariode Seguridad L2

48© 2005 Cisco Systems, Inc. All rights reserved. 10849_Icons_May2005 Cisco Public

Más Contramedidas

Page 49: Seminariode Seguridad L2

49© 2005 Cisco Systems, Inc. All rights reserved. 10849_Icons_May2005 Cisco Public

Storm Control

Page 50: Seminariode Seguridad L2

50© 2005 Cisco Systems, Inc. All rights reserved. 10849_Icons_May2005 Cisco Public

Rate Limiting

Page 51: Seminariode Seguridad L2

51© 2005 Cisco Systems, Inc. All rights reserved. 10849_Icons_May2005 Cisco Public

Priority Policing

Page 52: Seminariode Seguridad L2

52© 2005 Cisco Systems, Inc. All rights reserved. 10849_Icons_May2005 Cisco Public

Secure Shell

Page 53: Seminariode Seguridad L2

53© 2005 Cisco Systems, Inc. All rights reserved. 10849_Icons_May2005 Cisco Public

Configuration File Security

Page 54: Seminariode Seguridad L2

54© 2005 Cisco Systems, Inc. All rights reserved. 10849_Icons_May2005 Cisco Public

Power Over Ethernet Attacks

Page 55: Seminariode Seguridad L2

55© 2005 Cisco Systems, Inc. All rights reserved. 10849_Icons_May2005 Cisco Public

PoE Attacks

Page 56: Seminariode Seguridad L2

56© 2005 Cisco Systems, Inc. All rights reserved. 10849_Icons_May2005 Cisco Public

PoE Attacks: Contramedidas

Page 57: Seminariode Seguridad L2

57© 2005 Cisco Systems, Inc. All rights reserved. 10849_Icons_May2005 Cisco Public

PoE Attacks: Contramedidas

Page 58: Seminariode Seguridad L2

58© 2005 Cisco Systems, Inc. All rights reserved. 10849_Icons_May2005 Cisco Public

VLAN HOPPING ATTACK

Page 59: Seminariode Seguridad L2

59© 2005 Cisco Systems, Inc. All rights reserved. 10849_Icons_May2005 Cisco Public

VLAN HOPPING

Page 60: Seminariode Seguridad L2

60© 2005 Cisco Systems, Inc. All rights reserved. 10849_Icons_May2005 Cisco Public

VLAN HOPPING: CONTRAMEDIDAS

Page 61: Seminariode Seguridad L2

61© 2005 Cisco Systems, Inc. All rights reserved. 10849_Icons_May2005 Cisco Public

USANDO SU CATALYST PARA PROTEGERSE: ACLs

Page 62: Seminariode Seguridad L2

62© 2005 Cisco Systems, Inc. All rights reserved. 10849_Icons_May2005 Cisco Public

TIPOS DE ACCESS LISTS

Page 63: Seminariode Seguridad L2

63© 2005 Cisco Systems, Inc. All rights reserved. 10849_Icons_May2005 Cisco Public

TIPOS DE ACCESS LISTS

Page 64: Seminariode Seguridad L2

64© 2005 Cisco Systems, Inc. All rights reserved. 10849_Icons_May2005 Cisco Public

CONFIGURING VACLs

Page 65: Seminariode Seguridad L2

65© 2005 Cisco Systems, Inc. All rights reserved. 10849_Icons_May2005 Cisco Public

CONFIGURING VACLs

Page 66: Seminariode Seguridad L2

66© 2005 Cisco Systems, Inc. All rights reserved. 10849_Icons_May2005 Cisco Public

CONFIGURING VACLs

Page 67: Seminariode Seguridad L2

67© 2005 Cisco Systems, Inc. All rights reserved. 10849_Icons_May2005 Cisco Public

CONFIGURING VACLs

Page 68: Seminariode Seguridad L2

68© 2005 Cisco Systems, Inc. All rights reserved. 10849_Icons_May2005 Cisco Public

CONFIGURING VACLs

Page 69: Seminariode Seguridad L2

69© 2005 Cisco Systems, Inc. All rights reserved. 10849_Icons_May2005 Cisco Public

CONFIGURING VACLs

Page 70: Seminariode Seguridad L2

70© 2005 Cisco Systems, Inc. All rights reserved. 10849_Icons_May2005 Cisco Public

Monitoring VACLs – Capture Port

Page 71: Seminariode Seguridad L2

71© 2005 Cisco Systems, Inc. All rights reserved. 10849_Icons_May2005 Cisco Public

Monitoring VACLs – Capture Port

Page 72: Seminariode Seguridad L2

72© 2005 Cisco Systems, Inc. All rights reserved. 10849_Icons_May2005 Cisco Public

Monitoring VACLs – Capture Port


Recommended