cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
566
Views
0
Helpful
3
Replies

Port Security

Hi i have been studying about port security how do they set Port Security in an ISP how can they handle all the MAC-Flooding attack 

it would be really helpful if you put your resources or any books that can help evolve my knowledge

best regards. 

1 Accepted Solution

Accepted Solutions

M02@rt37
VIP
VIP

Hello @mohammedalrawiib 

Port security is often implemented at the network edge to control which devices can connect to the network.

From an ISP perspective, the implementation of storm control is a common practice to manage and control excessive broadcast, multicast, or unknown unicast traffic. Storm control helps prevent network disruptions caused by an overwhelming volume of such traffic. Dtorm control is just one element of a comprehensive network management and security strategy.

Apply rate limiting on specific types of traffic to control the rate at which certain packets are sent or received. This can help prevent network congestion and protect against certain types of attacks. 

Best regards
.ı|ı.ı|ı. If This Helps, Please Rate .ı|ı.ı|ı.

View solution in original post

3 Replies 3

M02@rt37
VIP
VIP

Hello @mohammedalrawiib 

Port security is often implemented at the network edge to control which devices can connect to the network.

From an ISP perspective, the implementation of storm control is a common practice to manage and control excessive broadcast, multicast, or unknown unicast traffic. Storm control helps prevent network disruptions caused by an overwhelming volume of such traffic. Dtorm control is just one element of a comprehensive network management and security strategy.

Apply rate limiting on specific types of traffic to control the rate at which certain packets are sent or received. This can help prevent network congestion and protect against certain types of attacks. 

Best regards
.ı|ı.ı|ı. If This Helps, Please Rate .ı|ı.ı|ı.

balaji.bandi
Hall of Fame
Hall of Fame

There are many products available in the market to prevent not only DDoS attack or many other attacks.

I have used some time back RADWARE for DDOS protection :

https://www.radware.com/2023-h1-global-threat-analysis-report/#menu-tab-ddos-protection

Some good explanation  - i collected when i was reading in the context of security.

https://datadome.co/learning-center/how-to-stop-ddos-attacks/

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

I have ONE ISP with SW and many CE, 
the costumer use PPPoE or use DHCP to get IP from ISP. 
then this SW must protect by 
Port-security (or use DHCP client-ID, this protect ISP from any unknown device)
use Storm-control to control the limit of broadcast send from CE to ISP

MHM

Review Cisco Networking for a $25 gift card