2.11 Switch Security Configuration

Mitigating MAC Address Table attacks

A very simple and most effective method to prevent CAM Table overflow attacks exists. This is to simply enable port security as already discussed.

Port security will limit the number of valid MAC Addresses allowed on a port/interface. You can manually configure MAC Addresses for a specific port/interface OR to make the switch dynamically learn a number of MAC Addresses.

As the port/interface configured with Port-Security receives a frame, it will immediately compare it to the list of secure source MAC Addresses and make a decision from there.