From the course: Cisco Certified Network Associate (CCNA) v1.1 (200-301) Cert Prep

Unlock this course with a free trial

Join today to access over 24,600 courses taught by industry experts.

Lesson 3: Layer 2 security features

Lesson 3: Layer 2 security features

(gentle music) - [Instructor] In this lesson, you're going to learn about three different ways of better protecting our Cisco switches. The first of those three ways is using a tool called DHCP Snooping. This can prevent a bad actor from maliciously putting a DHCP server on our network and trying to intercept those DHCP discover requests and potentially handing out incorrect information to our users. Our second feature is called Dynamic ARP Inspection. This can help protect us against a man in the middle attack where an attacker is falsifying ARP responses. For example, they might send an ARP response to our client saying, "Hey, the Mac address "of your default gateway is this," and they're giving their Mac address. They might be influencing that client or that victim to send their traffic to the attacker. We'll see how to protect against that, and then we'll wrap up this lesson with a look at port security, how we can limit the number of Mac addresses that are learnable off of a…

Contents