CCNA Network Security Fundamentals

Security runs through the whole CCNA 200-301 blueprint — from the threats themselves to the switch features that stop them. These CCNA network security fundamentals notes cover threats and attack vectors, VPN concepts, Layer 2 attacks and mitigations, port security, DHCP snooping and DAI, and device hardening with AAA. Finish with a free CCNA mock test to check what stuck.

Threats and Attack Vectors

The exam expects you to recognise common attacks and match each to its mitigation. Malware (viruses, worms, ransomware, trojans) spreads via email, downloads and removable media — mitigate with endpoint protection and patching. Phishing tricks users into surrendering credentials — mitigate with training and email filtering. DDoS floods a target with traffic from many sources (a DoS comes from one) — mitigate with upstream filtering and scrubbing. Man-in-the-middle intercepts communications — mitigate with encryption (TLS, IPsec).

Network-specific attacks get their own sections later in this domain, but learn the names now: rogue DHCP server hands out a malicious gateway to intercept traffic; ARP spoofing/poisoning maps the attacker's MAC to the gateway's IP; CAM table overflow floods a switch with fake MACs until it fails open and broadcasts everything; VLAN hopping (double-tagging) leaks frames between VLANs; MAC spoofing impersonates an allowed device.

The defensive mindset the exam rewards is defence in depth: no single control stops everything, so layer them — strong passwords and SSH and ACLs and port security and monitoring. When a question asks for the "best" mitigation, look for the layered answer, and match the control to the layer of the attack (a Layer 2 attack needs a Layer 2 control).

Key exam points

  • Know the attack→mitigation pairs: phishing→training/filtering, DDoS→upstream filtering, MITM→encryption.
  • DoS = one source; DDoS = many sources.
  • Layer 2 attacks: rogue DHCP, ARP spoofing, CAM overflow, VLAN hopping, MAC spoofing.
  • Defence in depth: layer controls; match the control to the attack's layer.

VPN Concepts

A VPN creates a secure tunnel across an untrusted network (usually the internet). Two architectures dominate. Site-to-site VPN connects whole networks — branch office to HQ — and is transparent to users; the routers/firewalls build the tunnel. Remote-access VPN connects individual users (a laptop, a phone) to the corporate network, typically with a client like Cisco AnyConnect plus user authentication.

IPsec is the protocol suite that secures site-to-site tunnels. Its moving parts: IKE (Internet Key Exchange, UDP 500 — UDP 4500 when NAT traversal is needed) negotiates the security association; ESP (Encapsulating Security Payload, IP protocol 50) provides encryption and integrity; AH (Authentication Header, IP protocol 51) provides integrity only, no encryption. The exam's key contrast: GRE alone does not encrypt — it's just encapsulation (IP protocol 47), commonly paired with IPsec when you need to tunnel multicast or routing protocols.

SSL/TLS VPNs (clientless or AnyConnect) run over HTTPS and are the usual remote-access choice. For the exam, the decision tree is simple: connecting networks → site-to-site IPsec; connecting users → remote-access (SSL/AnyConnect); need encryption → IPsec/ESP, never GRE alone; see "IKE" → UDP 500/4500.

Key exam points

  • Site-to-site = networks to networks (transparent to users). Remote-access = users to network (client + auth).
  • IPsec: IKE (UDP 500/4500) negotiates; ESP (IP 50) encrypts; AH (IP 51) integrity only.
  • GRE alone does NOT encrypt (IP protocol 47) — pair it with IPsec when needed.
  • Remote access typically uses SSL/TLS VPN (e.g. AnyConnect).

Layer 2 Attacks and Mitigations

Switches trust too easily, and each trust has an attack. CAM table overflow: the attacker floods thousands of fake source MACs; the CAM fills up and the switch fails open, flooding frames like a hub so the attacker can sniff them. Mitigation: port security limiting MACs per port. DHCP spoofing/starvation: a rogue server (or a starvation attack exhausting the real pool) hands clients a malicious gateway for a man-in-the-middle. Mitigation: DHCP snooping — only trusted ports may send DHCP offers.

ARP spoofing/poisoning: forged ARP replies map the attacker's MAC to the gateway's IP, diverting traffic. Mitigation: Dynamic ARP Inspection (DAI), which checks ARP packets against the DHCP snooping binding table. VLAN hopping via double-tagging: the attacker tags frames for a second VLAN, counting on the switch to strip only the outer tag. Mitigation: set the native VLAN to an unused VLAN and prune trunks. STP manipulation: a rogue switch claims a superior bridge ID to become root and intercept traffic. Mitigation: Root Guard and BPDU Guard.

The exam presents these as matched pairs — attack on the left, control on the right. Learn them as pairs: CAM overflow ↔ port security, rogue DHCP ↔ DHCP snooping, ARP spoofing ↔ DAI, VLAN hopping ↔ native-VLAN hygiene, rogue root bridge ↔ Root/BPDU Guard. A question describing symptoms ("hosts are getting the wrong gateway") is really asking you to name the attack, then the mitigation.

Key exam points

  • CAM overflow → port security. Rogue DHCP → DHCP snooping (trust only uplinks).
  • ARP spoofing → DAI (validates against the snooping binding table).
  • VLAN hopping (double-tagging) → native VLAN set to an unused VLAN; prune trunks.
  • STP manipulation → Root Guard + BPDU Guard. Learn each as an attack↔mitigation pair.

Port Security, DHCP Snooping and DAI

Port security caps the MAC addresses allowed on a switch port — the direct answer to CAM overflow and unauthorised devices. Configure on an access port:
switchport mode access
switchport port-security
switchport port-security maximum 2
switchport port-security mac-address sticky
switchport port-security violation restrict
Sticky learning remembers dynamically learned MACs as if configured. Violation modes: protect (silently drops excess frames), restrict (drops + logs/SNMP trap), shutdown (err-disables the port — the default). Verify with show port-security interface g0/1; recover an err-disabled port with shutdown then no shutdown.

DHCP snooping makes the switch a DHCP bouncer: ip dhcp snooping globally, ip dhcp snooping vlan 10 per VLAN, then ip dhcp snooping trust on uplink ports toward the real server — every other port is untrusted and its DHCP offers are dropped. As a bonus it builds the binding table (MAC ↔ IP ↔ VLAN ↔ port) that other features consume. Rate-limit DHCP on untrusted ports with ip dhcp snooping limit rate 10 to blunt starvation attacks.

DAI (Dynamic ARP Inspection) spends that binding table: ip arp inspection vlan 10 makes the switch drop ARP replies whose MAC/IP pairing doesn't match the table, killing ARP spoofing. Trust uplinks with ip arp inspection trust so legitimate infrastructure ARP isn't inspected. All three features chain together — snooping feeds DAI — which is exactly how the exam likes to test them.

Key exam points

  • Port security: maximum MACs, sticky learning; violations: protect (drop), restrict (drop+log), shutdown (err-disable, default).
  • DHCP snooping: trust only uplinks to the real server; builds the MAC↔IP binding table.
  • DAI validates ARP against the snooping binding table: ip arp inspection vlan <id>.
  • Recover err-disable with shutdown / no shutdown. Verify with show port-security.

Device Hardening and AAA

Start with the basics the exam checks by reflex. enable secret (strongly hashed) beats enable password (weak) — if both exist, the secret wins. service password-encryption obscures other passwords from shoulder-surfers (it's reversible, so it's obscurity, not security). Set security passwords min-length 10, add MOTD and login banners (banner motd #…#) with a proper warning — no "welcome", just authorised-use wording. Disable unused services and put no ip http server where the web UI isn't needed.

Management access must be encrypted: Telnet sends everything in clear text, so the exam's answer is always SSH. Minimum viable SSH config: hostname + ip domain-name set, crypto key generate rsa modulus 2048, ip ssh version 2, then on the VTY lines transport input ssh and login local with a local username (username admin privilege 15 secret …). Add exec-timeout and consider an access-class ACL restricting VTY access to management hosts.

AAA (Authentication, Authorisation, Accounting) centralises all of this on a server. Two protocols: TACACS+ (Cisco, TCP 49, encrypts the entire packet, separates AAA) for device administration, and RADIUS (open standard, UDP 1812/1813, encrypts only the password, combines authentication and authorisation) for network access like 802.1X Wi-Fi. Enable with aaa new-model, then define server and method lists. Exam shorthand: "which protocol for device admin with full packet encryption?" → TACACS+.

Key exam points

  • enable secret beats enable password; service password-encryption is obscurity, not security.
  • SSH only — never Telnet. Needs hostname, domain-name, RSA key, ip ssh version 2, transport input ssh.
  • Banners: MOTD/login with authorised-use wording. VTY: login local, exec-timeout, access-class ACL.
  • TACACS+ (TCP 49, full encryption, separate AAA) = device admin. RADIUS (UDP 1812/13) = network access.

Related CCNA study guides

Frequently asked questions

What are the key CCNA exam points for Threats and Attack Vectors?

For the CCNA 200-301 exam, remember: Know the attack→mitigation pairs: phishing→training/filtering, DDoS→upstream filtering, MITM→encryption. DoS = one source; DDoS = many sources. Layer 2 attacks: rogue DHCP, ARP spoofing, CAM overflow, VLAN hopping, MAC spoofing. Defence in depth: layer controls; match the control to the attack's layer.

What are the key CCNA exam points for VPN Concepts?

For the CCNA 200-301 exam, remember: Site-to-site = networks to networks (transparent to users). Remote-access = users to network (client + auth). IPsec: IKE (UDP 500/4500) negotiates; ESP (IP 50) encrypts; AH (IP 51) integrity only. GRE alone does NOT encrypt (IP protocol 47) — pair it with IPsec when needed. Remote access typically uses SSL/TLS VPN (e.g. AnyConnect).

What are the key CCNA exam points for Layer 2 Attacks and Mitigations?

For the CCNA 200-301 exam, remember: CAM overflow → port security. Rogue DHCP → DHCP snooping (trust only uplinks). ARP spoofing → DAI (validates against the snooping binding table). VLAN hopping (double-tagging) → native VLAN set to an unused VLAN; prune trunks. STP manipulation → Root Guard + BPDU Guard. Learn each as an attack↔mitigation pair.

What are the key CCNA exam points for Port Security, DHCP Snooping and DAI?

For the CCNA 200-301 exam, remember: Port security: maximum MACs, sticky learning; violations: protect (drop), restrict (drop+log), shutdown (err-disable, default). DHCP snooping: trust only uplinks to the real server; builds the MAC↔IP binding table. DAI validates ARP against the snooping binding table: ip arp inspection vlan <id>. Recover err-disable with shutdown / no shutdown. Verify with show port-security.

What are the key CCNA exam points for Device Hardening and AAA?

For the CCNA 200-301 exam, remember: enable secret beats enable password; service password-encryption is obscurity, not security. SSH only — never Telnet. Needs hostname, domain-name, RSA key, ip ssh version 2, transport input ssh. Banners: MOTD/login with authorised-use wording. VTY: login local, exec-timeout, access-class ACL. TACACS+ (TCP 49, full encryption, separate AAA) = device admin. RADIUS (UDP 1812/13) = network access.