03-09-2007 08:43 AM - edited 03-05-2019 02:48 PM
Hi EXPERTS!
I Have to know:
1)in when/where we design/use Ip dhcp snooping?
2)when/where we design/configure switchport no-negotiate mode with bpdu filter enable on each access port as per spanning tree best practices?
3)when/where we design/configure Cisco Content Swiched Network?
4)i want a useful link incluse like this operation:
on 6509 Core Switch Migration from SUP1A to SUP720 FABRIC MSFC with redundancy sup720
ur reply is very much appreciate
regards
ALI
03-09-2007 09:56 AM
Hello
any reply here
10xs
03-09-2007 11:59 PM
=>Features like DHCP snooping and DAI can be used to mitigate various ARP-based network exploits.
Please refer:
SAFE
Conf_Guide
Ideally, in a campus network with L2 access design, we have dhcp server on distribution layer. Thus, we assign dhcp server ports as trusted and keep rest as untrusted so that we do not recieve any DHCP server type response from anywhere else in the network.
2) "switchport noneg" is typically used while connecting to routers or third party devices that do not support DTP, to prevent inconsistencies while link negotiation and results in unconditional trunking.
BPDU filtering is not recommended as such by any best practice, and neither would I. If an attacker connects to a port with bpdu filering, the port will lose portfast status and start participating in stp, and can damage the network to some extent. Whatmore, after he's through and you connect some authorized device, it would take default stp time = 20-50 sec for him to be on the network. Thus, I would recommend using BPDU Guard anyday over BPDU filtering.
For further references:
DTP/Trunking:
BPDU Filtering:
3) Cisco Content Switches Network typically refers to the data center/server farm deployments using various techniques/designs/devices for load balancing traffic and L4-L7 services across multiple servers.
Some useful links:
http://www.cisco.com/en/US/products/hw/switches/ps708/tsd_products_support_series_home.html
Please rate as applicable.
Regards
Rajat Chauhan
03-10-2007 12:58 AM
HI Rajat Chauhan!
Appreciate ur valuable repy.Thanks a lot for ur reply
Regards
ALI
03-10-2007 01:00 AM
HELLO Rajat Chauhan!
the first 4th link doesn;t open need a CCO,Could you plz provide others
10xs
03-10-2007 01:12 AM
Hi Ali,
Sorry for that, here are public version of the links:
SAFE:
Conf_guide:
DTP/trunking:
http://www.cisco.com/en/US/products/hw/switches/ps700/products_tech_note09186a008012ecf3.shtml
bpdu filtering:
other:
http://www.cisco.com/en/US/products/hw/switches/ps708/tsd_products_support_series_home.html
Thanks
Rajat
03-10-2007 01:32 AM
Hi!
10xs for ur reply
Regards
ALI
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide