Juniper Networks
Log in
|
How to Buy
|
Contact Us
|
United States (Change)
Choose Country
Close

Choose Country

North America

  • United States

Europe

  • Deutschland - Germany
  • España - Spain
  • France
  • Italia - Italy
  • Россия - Russia
  • United Kingdom

Asia Pacific

  • Asean Region (Vietnam, Indonesia, Singapore, Malaysia)
  • Australia
  • 中国 - China
  • India
  • 日本 - Japan
  • 대한민국 - Korea
  • 台灣 - Taiwan
Solutions
Products & Services
Company
Partners
Support
Education
Community
Security Intelligence Center

Technical Documentation

Support
Technical Documentation
Content Explorer New
 
Enterprise MIBs
 
EOL Documentation
 
File Format Help
 
Glossary
 
Portable Libraries
 
 
Home > Support > Technical Documentation > EX Series > Port Security on EX Series Switches
Print
Rate and give feedback:  Feedback Received. Thank You!
Rate and give feedback: 
Close
This document helped resolve my issue.  Yes No

Additional Comments

800 characters remaining

May we contact you if necessary?

Name:  
E-mail: 
Submitting...

Port Security on EX Series Switches

  • Junos® OS for EX Series Switches, Release 12.1
  • Overview
  • Configuration
  • Administration
  • Troubleshooting
Security Features Overview

Security Features for EX Series Switches Overview

Port Security Overview

Port Security Overview

Understanding How to Protect Access Ports on EX Series Switches from Common Attacks

Understanding DHCP Snooping for Port Security

Understanding DAI for Port Security

Understanding MAC Limiting and MAC Move Limiting for Port Security on EX Series Switches

Understanding Trusted DHCP Servers for Port Security

Understanding IP Source Guard for Port Security on EX Series Switches

Understanding DHCP Option 82 for Port Security on EX Series Switches

Understanding Persistent MAC Learning (Sticky MAC)

Configuration Examples

Example: Configuring Basic Port Security Features

Example: Configuring MAC Limiting, Including Dynamic and Allowed MAC Addresses, to Protect the Switch from Ethernet Switching Table Overflow Attacks

Example: Configuring a DHCP Server Interface as Untrusted to Protect the Switch from Rogue DHCP Server Attacks

Example: Configuring MAC Limiting to Protect the Switch from DHCP Starvation Attacks

Example: Configuring DHCP Snooping and DAI to Protect the Switch from ARP Spoofing Attacks

Example: Configuring Allowed MAC Addresses to Protect the Switch from DHCP Snooping Database Alteration Attacks

Example: Configuring DHCP Snooping, DAI , and MAC Limiting on a Switch with Access to a DHCP Server Through a Second Switch

Example: Configuring IP Source Guard with Other EX Series Switch Features to Mitigate Address-Spoofing Attacks on Untrusted Access Interfaces

Example: Configuring IP Source Guard on a Data VLAN That Shares an Interface with a Voice VLAN

Example: Setting Up DHCP Option 82 with a Switch as a Relay Agent Between Clients and a DHCP Server

Example: Setting Up DHCP Option 82 with a Switch with No Relay Agent Between Clients and a DHCP Server

Example: Using CoS Forwarding Classes to Prioritize Snooped Packets in Heavy Network Traffic

Configuration Tasks

Configuring Port Security (CLI Procedure)

Configuring Port Security (J-Web Procedure)

Enabling DHCP Snooping (CLI Procedure)

Enabling DHCP Snooping (J-Web Procedure)

Enabling a Trusted DHCP Server (CLI Procedure)

Enabling a Trusted DHCP Server (J-Web Procedure)

Enabling Dynamic ARP Inspection (CLI Procedure)

Enabling Dynamic ARP Inspection (J-Web Procedure)

Configuring MAC Limiting (CLI Procedure)

Configuring MAC Limiting (J-Web Procedure)

Configuring MAC Move Limiting (CLI Procedure)

Configuring MAC Move Limiting (J-Web Procedure)

Setting the none Action on an Interface to Override a MAC Limit Applied to All Interfaces (CLI Procedure)

Configuring IP Source Guard (CLI Procedure)

Configuring Static IP Addresses for DHCP Bindings on Access Ports (CLI Procedure)

Setting Up DHCP Option 82 with the Switch as a Relay Agent Between Clients and DHCP Server (CLI Procedure)

Setting Up DHCP Option 82 on the Switch with No Relay Agent Between Clients and DHCP Server (CLI Procedure)

Configuring Autorecovery From the Disabled State on Secure or Storm Control Interfaces (CLI Procedure)

Configuring Persistent MAC Learning (CLI Procedure)

Configuration Statements

[edit ethernet-switching-options] Configuration Statement Hierarchy

[edit forwarding-options] Configuration Statement Hierarchy

allowed-mac

arp-inspection

circuit-id

dhcp-option82

dhcp-snooping-file

dhcp-trusted

disable-timeout

ethernet-switching-options

examine-dhcp

forwarding-class

interface

ip-source-guard

location

mac

mac-limit

mac-move-limit

no-allowed-mac-log

no-gratuitous-arp-request

persistent-learning

port-error-disable

prefix (for circuit-id)

prefix (for remote-id)

remote-id

secure-access-port

static-ip

timeout

traceoptions

use-interface-description

use-string

use-vlan-id

vendor-id

vlan (for secure-access port)

vlan (for static-ip)

write-interval

Routine Monitoring

Monitoring Port Security

Verifying That DHCP Snooping Is Working Correctly

Verifying That a Trusted DHCP Server Is Working Correctly

Verifying That DAI Is Working Correctly

Verifying That MAC Limiting Is Working Correctly

Verifying That MAC Move Limiting Is Working Correctly

Verifying That IP Source Guard Is Working Correctly

Verifying That the Port Error Disable Setting Is Working Correctly

Verifying That Persistent MAC Learning Is Working Correctly

Operational Commands

clear arp inspection statistics

clear dhcp snooping binding

clear dhcp snooping statistics

show arp inspection statistics

show dhcp snooping binding

show dhcp snooping statistics

show ethernet-switching table

show ip-source-guard

show system statistics arp

Knowledge Base

http://kb.juniper.net/

Troubleshooting Procedures

Troubleshooting Port Security

 

Related Documentation

  • EX Series
  • EX Series Switch Software Features Overview
 
 

Downloads

  • Download this page: Port Security on EX Series Switches PDF Document
  • Complete Software Guide PDF Document
 
 

Related Documentation

  • EX Series
  • EX Series Switch Software Features Overview
 
 
  • About Juniper
  • The New Network
  • Investor Relations
  • Press Releases
  • Newsletters
  • Juniper Offices
  • Resources
  • How to Buy
  • Partner Locator
  • Image Library
  • Visio Templates
  • Security Center
  • Community
  • Forums
  • Blogs
  • Junos Central
  • Social Media
  • Support
  • Technical Documentation
  • Knowledge Base (KB)
  • Software Downloads
  • Product Licensing
  • Contact Support
Site Map / RSS Feeds / Careers / Accessibility / Feedback / Privacy & Policy / Legal Notices
Copyright© 1999-2012 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out