[c-nsp] RES: RES: Large networks

Leonardo Gama Souza leonardo.souza at nec.com.br
Wed Aug 26 15:34:10 EDT 2009


You are right.
To be protected against IP spoofing you would need a VACL configured as
well.

>Private VLANs won't help you with ip-spoofing in the same subnet and
>hsrp-attacks and not against arp attacks (but these can be prevented
>using static arp-entries on the l3-device).
>
>Matthias



More information about the cisco-nsp mailing list