On TV.com: ADAM LAMBERT'S A Big Faker
BNET Business Network:
BNET
TechRepublic
ZDNet

January 31st, 2007

Layer 2 security; the forgotten front

Posted by George Ou @ 2:36 am

Categories: Desktop, Infrastructure, Networking, Security, Servers

Tags:

One of the fastest ways for hackers to breech security systems is to circumvent Layer 2 which is your LAN switching infrastructure.  Unfortunately that also happens to be one of the most overlooked aspects of Information Security with most security audits focusing on policy and compliance issues on the upper layers of the stack.  The vast majority of networks large or small that I have come across in my past career as an IT consultant lacked most of the basic defenses on their LAN switching infrastructure.

To help fix this situation, I created this free comprehensive guide "Essential lockdowns for Layer 2 switch security" to address all of the following issues.

  • Enable SSH and disable TELNET
  • Lock down VTP and SNMP security
  • Basic port lockdown
  • VLAN trunking lockdown
  • STP BPDU and Root guard
  • Prevent CAM table and DHCP bombing
  • Prevent DHCP, MAC, and IP spoofing
  • Limit the size of STP domains
  • Maintain the switch software to the latest stable build
  • A look at the future: 802.1x and NAP/NAC

A PDF version is also available for (free) registered users for offline viewing.

The consequences for not deploying these security mechanisms means that hackers who manage to break in to a single computer on your network will be able to expand their reach.  They'll be able to:

  • Sniff your internal LAN for passwords and break in to other critical systems
  • Crash your LAN and lock it up indefinitely
  • Nuke your LAN configuration and shut your whole network down
  • Take your phone system down if you're using IP Telephony

How locked down is your LAN switching infrastructure?

View Results

Loading ... Loading ...

George Ou is Technical Director of ZDNet. See his full profile and disclosure of his industry affiliations.

  • Talkback
  • Most Recent of 25 Talkback(s)
I'm not worried
"Do not pretend you didn't say these words because it's in black and white what you said in this thread."

That's right George - it is in black and white and anyone who reads it can see h... (Read the rest)
Posted by: bportlock Posted on: 02/01/07 You are currently: a Guest | | Terms of Use
Added to my list of things to do yesterday.  nucrash | 01/31/07
I wouldn't worry about it if I were you...  bportlock | 01/31/07
That's just a real foolish attitude  georgeou | 01/31/07
That's a realistic attitude  bportlock | 01/31/07
I am not for sure who can urinate farther  nucrash | 01/31/07
Take it easy...  bportlock | 01/31/07
No, you said don't worry about this stuff  georgeou | 01/31/07
I'm not worried  bportlock | 02/01/07
Let's not start moral equivalency here  georgeou | 01/31/07
I never said that  georgeou | 01/31/07
The Best Security is Physical Security  D. T. Schmitz | 01/31/07
One doesn't substitute for the other  georgeou | 01/31/07
Possible? Cost vs Liability Cost  D. T. Schmitz | 01/31/07
Point is you can't prevent patients from being near RJ45 jacks  georgeou | 01/31/07
HIPAA and Patients  D. T. Schmitz | 01/31/07
I can agree with the thin clients for medical use  georgeou | 01/31/07
Good article George  toadlife | 01/31/07
You're in the majority  georgeou | 01/31/07
You'll love this  toadlife | 01/31/07
Thank god I don't have a ticket system yet  nucrash | 01/31/07
Ticketing systems are a good thing  toadlife | 01/31/07
So long as it's not overbearing  georgeou | 01/31/07
One ticket for each port  toadlife | 01/31/07
What really bugs me is when I ask fellow IT workers to do something  georgeou | 01/31/07
That's the problem with security, it's not important till it's too late  georgeou | 01/31/07

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

Click Here
advertisement

Recent Entries

Top Rated

    advertisement

    Archives

    ZDNet Blogs

    White Papers, Webcasts, and Downloads