
Summary 265
• Within VLANs, ARP spoofing (hacking tools hunt, arpspoof), CAM overflow
(hacking tool macof), DoS against spanning tree, and DoS storms (a hacking tool
exists) can be done. For ARP spoofing and CAM overflow prevention, look at port
security. Also, disable the spanning tree on the router port by hard coding the root
bridge, for example.
These are not extensive and are the most obvious best practices for Layer 2 deployments.
Summary
This chapter provided use cases, application examples, and best practice guidelines for the
key principles discussed in this book.
We have also offered security notes to these use cases in order to apprise ...