[c-nsp] Protecting the network from ARP Poisoning

techtalm techtalm at gmail.com
Sun Jan 23 01:32:35 EST 2011


 

Hi,

 

How can I protect an SP network from ARP poisoning? 

I can't using DAI/DHCP snooping because no DHCP is activated on the servers
segment and adding their MAC's manually seems great burden.

Private VLAN are still exposed due to the fact that the gateway port is in
promiscuous mode, or I'm wrong?

Any suggestions?

 

Thx,

Tal

 

 



More information about the cisco-nsp mailing list