Virtual LAN (VLAN)
A logical grouping of computers based on switch port.
MAC filtering/port security
A switch feature that restricts connection to a given port based on the MAC address.
Port authentication
A switch feature that follows the 802.1x protocol to allow only authenticated devices to connect.
Content-addressable
memory (CAM) table
A table maintained by a switch that contains MAC addresses and their corresponding port locations.
Dynamic Host Configuration protocol (DHCP) snooping
A security feature on some switches that filters out untrusted DHCP messages.
Dynamic ARP
Inspection (DAI)
A security feature on some switches that verifies each ARP request has a valid IP to MAC binding.
MAC flooding
An attack that overloads a switch’s MAC forwarding table to make the switch function like a hub.
ARP spoofing
An attack in which the attacker’s MAC address is associated with the IP address of a target’s device.
VLAN hopping
An attack in which the actor routes network traffic from one VLAN to another, avoiding VLAN segmentation.
Double tagging
An attack in which the attacking host adds two VLAN tags instead of one to the header of the frames that it transmits.
MAC spoofing
An attack in which the source MAC address is changed in the header of a frame.
Dynamic Trunking
Protocol (DTP)
An unsecure protocol that could allow unauthorized devices to modify a switch’s configuration.