Security Fundamentals // Lesson 07

Layer 2 Security.

Configure and verify DHCP snooping, Dynamic ARP Inspection and port security as a coordinated access-layer defence.

DHCP snoopingDAIPort securityTrust boundaryBinding table
01 // Mental model

Start with the big picture.

Permits server replies only from trusted ports and builds a binding table from legitimate leases.

CCNA focus: Trust only the infrastructure-facing ports that truly need it. An incorrect trust boundary can either block valid service or allow an attacker to bypass inspection.
02 // Building blocks

Know what each part does.

01

DHCP snooping

Permits server replies only from trusted ports and builds a binding table from legitimate leases.

02

DAI

Validates ARP messages using trusted information such as the DHCP snooping binding table.

03

Port security

Limits which source MAC addresses may use an access port and defines violation action.

04

Trust boundary

Uplinks toward authorised infrastructure are trusted; ordinary client-facing ports remain untrusted.

03 // Compare and recognise

Read the clues.

ItemWhat to remember
ProtectDrops violating frames and increments a counter without shutting the port.
RestrictDrops and logs/counts violations without err-disabling the port.
ShutdownErr-disables the port on violation; the common default.
StickyDynamically learned secure MAC addresses are added to the running configuration.
04 // Access switch baseline

Access switch baseline.

SW1(config)# ip dhcp snooping
SW1(config)# ip dhcp snooping vlan 10
SW1(config)# ip arp inspection vlan 10
SW1(config)# interface gigabitEthernet 0/1
SW1(config-if)# ip dhcp snooping trust
SW1(config-if)# ip arp inspection trust
SW1(config)# interface gigabitEthernet 0/10
SW1(config-if)# switchport port-security
SW1(config-if)# switchport port-security maximum 2
SW1(config-if)# switchport port-security mac-address sticky
SW1# show ip dhcp snooping binding

Read the example from top to bottom, then verify the resulting state. Configuration is only complete when the output matches the intended design.

05 // Exam and troubleshooting

Turn facts into a method.

  • Drops violating frames and increments a counter without shutting the port.
  • Drops and logs/counts violations without err-disabling the port.
  • Err-disables the port on violation; the common default.
  • Dynamically learned secure MAC addresses are added to the running configuration.
Exam checkpoint: Trust only the infrastructure-facing ports that truly need it. An incorrect trust boundary can either block valid service or allow an attacker to bypass inspection.
06 // Check yourself

Layer 2 Security quiz.

1. What table does DHCP snooping build?

2. What information can DAI use to validate ARP?

3. Which ports should usually be DHCP snooping trusted?

4. Which port-security mode err-disables the port by default?

5. What does sticky learning do?

Score: 0 / 5