Soru

Zorluk: OrtaLayer 2 Security Features (Port Security, DHCP Snooping, DAI)

A network administrator is implementing Layer 2 security controls on Cisco Catalyst access switches. Match each Layer 2 security feature mechanism on the left to its corresponding operational behavior on the right.

  • DHCP Snooping Option 82 InsertionAttaches relay agent information (circuit ID/remote ID) to DHCP requests on untrusted ports
  • Dynamic ARP Inspection (DAI)Intercepts and checks ARP requests against the DHCP binding database on untrusted interfaces
  • Port Security Sticky MAC LearningDynamically converts learned MAC addresses into running configuration entries
  • Port Security Restrict Violation ModeDrops unauthorized frames, increments the violation counter, and sends a Syslog message without shutting down the interface

Cevap

DHCP Snooping Option 82 Insertion attaches relay agent information to DHCP requests on untrusted ports. Dynamic ARP Inspection (DAI) intercepts and checks ARP requests against the DHCP binding database on untrusted interfaces. Port Security Sticky MAC Learning dynamically converts learned MAC addresses into running configuration entries. Port Security Restrict Violation Mode drops unauthorized frames, increments the violation counter, and sends a Syslog message without shutting down the interface.
Each feature is paired with its precise Layer 2 operational behavior. DHCP Snooping Option 82 inserts circuit details into client requests. DAI mitigates ARP poisoning by cross-referencing ARP headers against the DHCP snooping database. Sticky MAC converts dynamic address learning into explicit running-configuration statements. Restrict mode drops offending frames and logs an alert while preserving link availability.

Adım Adım Çözüm

1
Analyze DHCP Snooping Option 82 mechanism
Identified that Option 82 adds relay agent metadata (such as switch chassis ID and port interface ID) to client requests on untrusted ports.
Option 82 provides location information to help DHCP servers assign IP addresses and policy parameters.
2
Analyze Dynamic ARP Inspection (DAI) verification mechanism
Determined that DAI validates incoming ARP packets against IP-to-MAC mappings stored in the DHCP snooping binding table.
DAI prevents ARP spoofing and poisoning by dropping invalid ARP packets on untrusted ports.
3
Examine Port Security sticky MAC functionality
Confirmed that sticky MAC dynamically discovers connected devices and writes them to running-config as static MAC entries.
Sticky MAC saves administrators from manually entering host MAC addresses while enforcing access restrictions.
4
Differentiate Port Security violation modes (protect vs restrict vs shutdown)
Matched restrict mode to dropping frames, logging Syslog messages, and incrementing violation counters without err-disabling the interface.
Protect mode drops frames silently without logging, whereas shutdown mode disables the interface entirely.

Anahtar Kavram

Layer 2 Security Mechanisms and Operational Characteristics
Bu soruyu puanla