Radiance 10/100 Mbps Services Line Card
26
Once a management VID has been configured, set it back to 0 to disable
VLAN management.
The R821 transparently passes reserved multicast protocols such as
IEEE 802.3ad, BPDU, GMRP, and GVRP. Transporting these protocols,
however, can introduce additional possibilities for denial-of-service
attacks including traffic volume from:
•
MAC addresses 01-80-C2-00-00-00 through 01-80-C2-00-00-10
— BPDU
— 802.3 slow protocols (LACP, Marker and OAM)
•
GMRP and GVRP
The following table describes the misuses that could cause denial of
service when using reserved multicast protocols along with the various
management configurations.
No
Management
VLAN
(both ports)
DEFAULT
SETTING
No security. Any device connected to
either port can manage the R821.
User could respond to
ARP and steal IP
address.
Table 3: R821 Management Vulnerabilities When Using Reserved
Multicast Protocols
Configuration
Vulnerabilities
Management
VLAN (single port)
with reserved
multicast
Denial of service through misuse of reserved multicast
address or 01-80-C2-00-00-02.
No Management
VLAN (single port)
User could respond to ARP and steal R821’s IP address.
Management
VLAN (both ports)
with reserved
multicast
Denial of service through misuse of reserved multicast or
unicast MAC address.
No Management
VLAN (both ports)
with reserved
multicast
Denial of service through misuse of reserved multicast,
unicast, or 01-80-C2-00-00-02 MAC address. User could
respond to ARP and steal the IP address.
Table 2: R821 Management Options and Vulnerabilities (Continued)
Configuration Configuration Description
Vulnerabilities
Содержание R821-1S
Страница 8: ...Radiance 10 100 Mbps Services Line Card 6...
Страница 14: ...Radiance 10 100 Mbps Services Line Card 12...
Страница 118: ...Radiance 10 100 Mbps Services Line Card 116...
Страница 126: ...Radiance 10 100 Mbps Services Line Card 124...