Layer 2 protocols such as DHCP and ARP were designed for trusted networks and have no authentication. An attacker on an access port can exploit that: a rogue DHCP server can hand out itself as the default gateway to intercept traffic, ARP spoofing can redirect traffic through the attacker (a man-in-the-middle), and IP spoofing can make an attacker's traffic appear to come from another host. Cisco switches provide three features that build on each other to stop these attacks.
Keep reading for free
Create a free StudyToCert account to read the rest of this lesson: 5 more sections, 5 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.