Section 10.0: Security Violations (6 points)

10.1. Smurf Attack (3 points)

  1. AAA/CA server in VLAN-2 is getting a smurf attack.

  2. Configure access restriction to prevent this from happening again in the future.

  3. You do not have access to the PIX, IDS, or any router in the network to secure this.

  4. You do not have access to the AAA/CA server to configure anything on it.

  5. With these limitations, your task is to secure this.

10.2. Basic VLAN Hopping Attack (3 points)

  1. An unknown device can spoof switch2 to believe it is a valid switch that needs trunking.

  2. If the attacker succeeds in negotiating the trunk with switch2, it can send and receive traffic on all VLANs configured.

  3. Protect switch2 to prevent this type of attack.

Get CCIE Security Practice Labs now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.