Techerest

IP Source Guard บน Cisco Switch คืออะไร? ป้องกัน IP Spoofing ด้วย DHCP Snooping

หลังจากทำความเข้าใจ DHCP Snooping และ Dynamic ARP Inspection (DAI) แล้ว Security Feature ลำดับต่อไปที่ควรรู้จักคือ IP Source Guard หรือ IPSG ซึ่งช่วยควบคุม Source IP Traffic ที่เข้าสู่ Cisco Switch ผ่าน Access Port

IP Source Guard สามารถนำข้อมูลจาก DHCP Snooping Binding Database มาใช้สร้างเงื่อนไขสำหรับตรวจสอบ Traffic ว่าต้นทางสอดคล้องกับ IP Address, MAC Address, VLAN และ Interface ที่ Switch เรียนรู้ไว้หรือไม่ ตามความสามารถและ Configuration ของ Platform

แนวคิดนี้ช่วยลดความเสี่ยงจาก IP Spoofing ซึ่งเป็นกรณีที่อุปกรณ์ส่ง Packet โดยใช้ Source IP Address ที่ไม่ควรถูกใช้งานจาก Port นั้น

ภาค 1: ทำความเข้าใจ IP Spoofing

IP Spoofing คืออะไร?

IP Spoofing คือการสร้างหรือส่ง IP Packet โดยกำหนด Source IP Address ให้เป็น Address อื่น แทนที่จะใช้ Source IP ที่ควรถูกใช้โดยอุปกรณ์นั้น

ตัวอย่างเชิงแนวคิด:

PC-A

IP จริง
192.168.10.100

แต่ส่ง Packet โดยใช้

Source IP
192.168.10.50

Switch Layer 2 แบบพื้นฐาน ไม่ได้ตัดสินใจ Forward Frame จาก Source IP Address แต่ใช้ข้อมูล Layer 2 เช่น MAC Address และ VLAN

ดังนั้นหากไม่มี Security Control เพิ่มเติม Switch อาจไม่ได้ตรวจสอบว่า Source IP Address ใน Packet เหมาะสมกับ Access Port นั้นหรือไม่

IP Spoofing มีความเสี่ยงอย่างไร?

การปลอม Source IP สามารถเกี่ยวข้องกับปัญหาหลายประเภท เช่น:

  • การปลอมตัวเป็น IP Address ของอุปกรณ์อื่น
  • การหลีกเลี่ยง Policy ที่พึ่งพา Source IP เพียงอย่างเดียว
  • การสร้าง Traffic ที่มี Source Address ไม่ถูกต้อง
  • การรบกวนการทำงานของ Network
  • ทำให้ Logging และ Troubleshooting ซับซ้อนขึ้น
IP Source Guard เป็น Security Control บริเวณ Access Layer แต่ไม่ควรถูกใช้แทน Firewall, ACL, 802.1X, Endpoint Security หรือ Identity-based Access Control

ภาค 2: IP Source Guard

IP Source Guard คืออะไร?

IP Source Guard — IPSG เป็น Layer 2 Security Feature บน Cisco Switch ที่รองรับ ซึ่งช่วยจำกัด Source IP Traffic ที่สามารถเข้าสู่ Network ผ่าน Layer 2 Port

แนวคิดพื้นฐาน:

Client
  |
  | IP Packet
  v
Access Port
  |
  v
IP Source Guard
  |
  +---- Valid Source ----> Forward
  |
  +---- Invalid Source --> Drop

IPSG สามารถใช้ข้อมูลจาก DHCP Snooping Binding Database เพื่อสร้าง Source Binding สำหรับ Client ที่ได้รับ IP ผ่าน DHCP

IP Source Guard กับ DHCP Snooping Binding

จากบทความ DHCP Snooping Switch สามารถเรียนรู้ข้อมูล เช่น:

MAC Address       IP Address       VLAN   Interface
----------------------------------------------------
AAAA.AAAA.AAAA    192.168.10.101   10     Gi1/0/5
BBBB.BBBB.BBBB    192.168.10.102   10     Gi1/0/6

ข้อมูลนี้ทำให้ Switch ทราบว่า:

Gi1/0/5
   |
   +-- VLAN 10
   |
   +-- IP 192.168.10.101
   |
   +-- MAC AAAA.AAAA.AAAA

เมื่อเปิด IP Source Guard บน Gi1/0/5 Switch สามารถนำ Binding มาใช้สร้าง Source Filter เพื่อควบคุม Traffic จาก Port ดังกล่าว

IP Source Guard ทำงานอย่างไร?

ลำดับการทำงานเชิงแนวคิด:

Client
   |
   | DHCP Request
   v
Cisco Switch
   |
   v
DHCP Snooping
   |
   v
DHCP Transaction Valid
   |
   v
Binding Database
   |
   +-- IP
   +-- MAC
   +-- VLAN
   +-- Interface
   |
   v
IP Source Guard
   |
   v
Source Filter
   |
   +---- Match ----> Forward
   |
   +---- No Match -> Drop

ดังนั้น DHCP Snooping ไม่ได้มีหน้าที่เพียงป้องกัน Rogue DHCP Server แต่ยังสร้างฐานข้อมูล ที่ Security Feature อื่นสามารถนำไปใช้ต่อได้

ตั้งค่า IP Source Guard บน Cisco Switch

สมมติ Network:

VLAN 10 = USERS

Gi1/0/1 - 20
Client Access Ports

Gi1/0/24
Trusted DHCP Path

Step 1 — เปิด DHCP Snooping

Switch# configure terminal

Switch(config)# ip dhcp snooping
Switch(config)# ip dhcp snooping vlan 10

Step 2 — กำหนด DHCP Snooping Trusted Port

สมมติ Gi1/0/24 เป็นเส้นทางที่ DHCP Server Responses เข้ามา:

Switch(config)# interface gigabitEthernet 1/0/24
Switch(config-if)# ip dhcp snooping trust
Switch(config-if)# exit

Step 3 — ตรวจสอบ DHCP Binding

Switch# show ip dhcp snooping binding

ก่อนเปิด IPSG ควรตรวจสอบว่า Client ได้รับ DHCP Lease และ Binding Database มีข้อมูลถูกต้อง

Step 4 — เปิด IP Source Guard

บน Access Port ที่รองรับ สามารถใช้:

Switch(config)# interface gigabitEthernet 1/0/5
Switch(config-if)# ip verify source
Switch(config-if)# exit

จากนั้น Switch สามารถสร้าง Source Filtering Information จาก Binding ที่เกี่ยวข้อง ตาม Platform และ Configuration

อย่าเปิด ip verify source บน Production Access Port ก่อนตรวจสอบ DHCP Snooping Binding และ Static IP Devices เพราะ Client ที่ไม่มี Binding ที่ระบบยอมรับอาจถูก Block

IP Source Guard ตรวจสอบ MAC Address ได้หรือไม่?

Cisco Platform บางรุ่นรองรับ Source IP และ Source MAC Verification เพิ่มเติม

ตัวอย่าง Syntax ที่พบในบาง Platform:

Switch(config-if)# ip verify source port-security

แนวคิดคือการตรวจสอบเพิ่มเติมว่า Traffic สอดคล้องกับทั้ง Source IP Binding และ Layer 2 Source MAC Information

Expected Binding

IP
192.168.10.101

MAC
AAAA.AAAA.AAAA

VLAN
10

Port
Gi1/0/5
คำสั่งและความสามารถของ ip verify source แตกต่างกันตาม Cisco Switch Model, IOS/IOS XE Version และ Feature Set ควรตรวจสอบ Command Reference ของอุปกรณ์จริงก่อน Configuration

Static IP กับ IP Source Guard

ประเด็นสำคัญเกิดขึ้นเมื่อ Client ไม่ได้รับ IP จาก DHCP แต่กำหนด Static IP ด้วยตนเอง

Printer
 |
 +-- IP 192.168.10.50
 |
 +-- Static IP
 |
 +-- No DHCP Transaction

เมื่อไม่มี DHCP Transaction Switch อาจไม่มี Dynamic DHCP Snooping Binding สำหรับอุปกรณ์นั้น

บน Platform ที่รองรับ สามารถใช้ Static IP Source Binding เพื่อกำหนด Mapping ที่ได้รับอนุญาต

ตัวอย่างแนวคิด:

Switch(config)# ip source binding aaaa.bbbb.cccc vlan 10 192.168.10.50 interface gigabitEthernet 1/0/10

จากนั้นสามารถตรวจสอบ Binding ด้วยคำสั่งที่ Platform รองรับ เช่น:

Switch# show ip source binding
Static Binding ต้องตรงกับ MAC Address, VLAN, IP Address และ Interface จริง หากกำหนดผิด อุปกรณ์ที่ถูกต้องอาจไม่สามารถสื่อสารได้

ภาค 3: DHCP Snooping + DAI + IP Source Guard

สาม Security Features ทำงานต่างกันอย่างไร?

ทั้งสาม Feature มีความสัมพันธ์กัน แต่ไม่ได้ทำหน้าที่เหมือนกัน

Feature สิ่งที่ตรวจสอบ ความเสี่ยงที่ช่วยลด
DHCP Snooping DHCP Messages Rogue DHCP Server
Dynamic ARP Inspection ARP Messages ARP Spoofing / Poisoning
IP Source Guard Source IP Traffic ที่ Access Port IP Spoofing

ภาพรวม:

                  DHCP Client
                       |
                       v
              +------------------+
              | DHCP Snooping    |
              +------------------+
                       |
                       v
              Binding Database
                       |
              +--------+--------+
              |                 |
              v                 v
     +----------------+  +----------------+
     |      DAI       |  |      IPSG      |
     +----------------+  +----------------+
              |                 |
              v                 v
        ARP Validation      Source IP
                            Validation

DHCP Snooping

Question:

"DHCP Server Message นี้
มาจาก Port ที่ได้รับอนุญาตหรือไม่?"

Dynamic ARP Inspection

Question:

"ARP Mapping นี้
สอดคล้องกับ Binding
ที่เชื่อถือได้หรือไม่?"

IP Source Guard

Question:

"Source IP นี้
ควรได้รับอนุญาตให้ส่ง Traffic
จาก Port นี้หรือไม่?"

ตัวอย่าง Layer 2 Access Security Architecture

                   DHCP Server
                        |
                        |
                  Trusted Path
                        |
                 +-------------+
                 | Cisco Switch|
                 +-------------+
                   /    |    \
                  /     |     \
                 /      |      \
              PC-A    PC-B    PC-C
                |       |       |
                +-------+-------+
                        |
              Access / Untrusted
                     Ports


Security Controls

DHCP Snooping
      |
      +---- Rogue DHCP Protection
      |
      +---- Binding Database
                 |
        +--------+--------+
        |                 |
        v                 v
       DAI               IPSG
        |                 |
        v                 v
   ARP Validation     Source IP
                      Validation

หากต้องการเพิ่ม Security สามารถนำ Feature อื่นเข้ามาร่วมด้วย เช่น:

  • Port Security
  • 802.1X
  • VLAN Segmentation
  • ACL
  • Firewall
  • Endpoint Security
  • Network Monitoring

แนวทางนี้เรียกว่า Defense in Depth คือไม่พึ่ง Security Control เพียงตัวเดียว

ภาค 4: Troubleshooting IP Source Guard

เปิด IP Source Guard แล้ว Client ใช้งานไม่ได้ ตรวจอะไรบ้าง?

หาก Client ใช้งานได้ก่อนเปิด IPSG แต่ใช้งานไม่ได้หลังเปิด ควรตรวจสอบตามลำดับ

1. ตรวจสอบ Interface

Switch# show interfaces status

2. ตรวจสอบ VLAN

Switch# show vlan brief

3. ตรวจสอบ Switchport

Switch# show interfaces gigabitEthernet 1/0/5 switchport

4. ตรวจสอบ DHCP Snooping

Switch# show ip dhcp snooping

ตรวจสอบว่า DHCP Snooping เปิดบน VLAN ถูกต้อง และ Trusted Path ถูกกำหนดตรงกับ Network Design

5. ตรวจสอบ DHCP Snooping Binding

Switch# show ip dhcp snooping binding

ตรวจสอบว่า Client มี:

  • IP Address ถูกต้อง
  • MAC Address ถูกต้อง
  • VLAN ถูกต้อง
  • Interface ถูกต้อง

6. ตรวจสอบ IP Source Binding

Switch# show ip source binding

7. ตรวจสอบ IP Source Guard Configuration

คำสั่งตรวจสอบเฉพาะ อาจแตกต่างตาม Platform จึงควรตรวจสอบ Running Configuration ของ Interface ร่วมด้วย

Switch# show running-config interface gigabitEthernet 1/0/5

8. ตรวจสอบ Client

Windows:

ipconfig /all

หาก Client ใช้ DHCP สามารถทดสอบ Renew Lease:

ipconfig /release
ipconfig /renew

9. ตรวจสอบ Static IP

หาก Client ใช้ Static IP ตรวจสอบว่ามี Static Source Binding หรือ Configuration ที่รองรับ Client ดังกล่าวหรือไม่

10. ตรวจสอบ Log

Switch# show logging

ใช้ตรวจสอบ Event ที่อาจเกี่ยวข้องกับ DHCP Snooping, IPSG, Port Security หรือ Interface State

Cisco Lab: DHCP Snooping + DAI + IP Source Guard

Lab นี้ใช้รวมความรู้จาก สามบทความเข้าด้วยกัน

Topology

                 DHCP Server
                     |
                     |
                  Gi1/0/24
                     |
              +--------------+
              | Cisco Switch |
              +--------------+
                /          \
               /            \
          Gi1/0/5          Gi1/0/6
             |                |
           PC-A             PC-B

             VLAN 10

Step 1 — สร้าง VLAN

Switch(config)# vlan 10
Switch(config-vlan)# name USERS
Switch(config-vlan)# exit

Step 2 — กำหนด Access Ports

Switch(config)# interface range gigabitEthernet 1/0/5 - 6
Switch(config-if-range)# switchport mode access
Switch(config-if-range)# switchport access vlan 10
Switch(config-if-range)# spanning-tree portfast
Switch(config-if-range)# exit

Step 3 — DHCP Snooping

Switch(config)# ip dhcp snooping
Switch(config)# ip dhcp snooping vlan 10

Step 4 — Trust DHCP Server Path

Switch(config)# interface gigabitEthernet 1/0/24
Switch(config-if)# ip dhcp snooping trust
Switch(config-if)# exit

Step 5 — ให้ Client รับ DHCP ก่อน

ตรวจสอบ:

Switch# show ip dhcp snooping binding

ควรเห็น Binding ของ PC-A และ PC-B ก่อนดำเนินการขั้นถัดไป

Step 6 — เปิด DAI

Switch(config)# ip arp inspection vlan 10

หาก Gi1/0/24 เป็น DAI Trusted Infrastructure ตาม Topology:

Switch(config)# interface gigabitEthernet 1/0/24
Switch(config-if)# ip arp inspection trust
Switch(config-if)# exit

Step 7 — เปิด IP Source Guard

Switch(config)# interface range gigabitEthernet 1/0/5 - 6
Switch(config-if-range)# ip verify source
Switch(config-if-range)# exit

Step 8 — ตรวจสอบทั้งหมด

show ip dhcp snooping
show ip dhcp snooping binding
show ip arp inspection
show ip source binding
show mac address-table

Step 9 — ทดสอบ Connectivity

จาก PC:

ipconfig /all
arp -a
ping 192.168.10.1

จากนั้นตรวจสอบว่า IP Address, Gateway และ Binding ตรงกับ Configuration ที่คาดไว้

Step 10 — ทดสอบเฉพาะใน Lab

สามารถเปลี่ยน Static IP ของ Client เป็น Address ที่ไม่มี Binding เพื่อศึกษาพฤติกรรมของ IPSG ใน Lab Environment

การทดลอง Source IP ที่ไม่ตรง Binding ควรทำเฉพาะใน Lab หรือ Network ที่ได้รับอนุญาตเท่านั้น ไม่ควรทดลองบน Production Network เพราะอาจทำให้ Connectivity ของระบบจริงได้รับผลกระทบ

คำสั่ง Cisco ที่ควรรู้

Command หน้าที่
ip dhcp snooping เปิด DHCP Snooping
ip dhcp snooping vlan 10 เปิด DHCP Snooping บน VLAN 10
ip dhcp snooping trust กำหนด DHCP Trusted Interface
show ip dhcp snooping ตรวจสอบ DHCP Snooping
show ip dhcp snooping binding ตรวจสอบ DHCP Snooping Binding
ip arp inspection vlan 10 เปิด Dynamic ARP Inspection
ip arp inspection trust กำหนด DAI Trusted Interface
show ip arp inspection ตรวจสอบ DAI
ip verify source เปิด IP Source Guard บน Interface
show ip source binding ตรวจสอบ IP Source Bindings
show mac address-table ตรวจสอบ MAC Address Table
show running-config interface ... ตรวจสอบ Configuration ของ Interface
show logging ตรวจสอบ System Log

คำถามที่พบบ่อย — FAQ

IP Source Guard คืออะไร?

IP Source Guard หรือ IPSG เป็น Security Feature ที่ช่วยควบคุม Source IP Traffic ที่เข้าสู่ Cisco Switch ผ่าน Layer 2 Access Port ตาม Source Binding ที่ Switch ใช้อ้างอิง

IP Source Guard ป้องกันอะไร?

IPSG ช่วยลดความเสี่ยงจาก Source IP Spoofing โดยจำกัดว่า Source IP ใด สามารถส่ง Traffic ผ่าน Interface ที่กำหนดได้

IP Source Guard ใช้ข้อมูลจากที่ไหน?

สำหรับ DHCP Client IPSG สามารถใช้ DHCP Snooping Binding Database ซึ่งมีข้อมูลเกี่ยวกับ IP Address, MAC Address, VLAN และ Interface

ต้องเปิด DHCP Snooping ก่อน IP Source Guard หรือไม่?

สำหรับ Dynamic DHCP Bindings DHCP Snooping เป็นองค์ประกอบสำคัญ เพราะสร้าง Binding Database ที่ IPSG สามารถนำไปใช้สร้าง Source Filters

IP Source Guard กับ DAI เหมือนกันหรือไม่?

ไม่เหมือนกัน DAI เน้นตรวจสอบ ARP Messages ส่วน IP Source Guard เน้นตรวจสอบ Source IP Traffic ที่ Access Port

IP Source Guard ใช้กับ Static IP ได้หรือไม่?

สามารถรองรับได้บน Platform และ Configuration ที่เหมาะสม แต่ Static Client ไม่มี Dynamic DHCP Binding จึงอาจต้องกำหนด Static IP Source Binding หรือกลไกอื่นที่ Platform รองรับ

IP Source Guard ใช้แทน Port Security ได้หรือไม่?

ไม่ได้โดยตรง IPSG และ Port Security ควบคุมคนละส่วนของ Access Layer Security และสามารถนำมาใช้ร่วมกัน ตาม Network Design

IP Source Guard ใช้แทน Firewall ได้หรือไม่?

ไม่ได้ IPSG เป็น Access Layer Security Control สำหรับ Source Validation ไม่ได้ทำหน้าที่แทน Stateful Firewall, Application Security หรือ Security Policy ระหว่าง Network Zones

สรุป

IP Source Guard — IPSG เป็น Layer 2 Security Feature ที่ช่วยควบคุม Source IP Traffic จาก Access Port และลดความเสี่ยงจาก IP Spoofing

สำหรับ DHCP Client IPSG สามารถใช้ข้อมูลจาก DHCP Snooping Binding Database เพื่อทราบความสัมพันธ์ระหว่าง IP Address, MAC Address, VLAN และ Interface

เมื่อมองร่วมกับบทความก่อนหน้า จะเห็น Layer 2 Security Chain ชัดเจน:

DHCP Snooping
     |
     +---- ป้องกัน Rogue DHCP
     |
     +---- สร้าง Binding Database
                  |
          +-------+-------+
          |               |
          v               v
         DAI             IPSG
          |               |
          v               v
    ARP Spoofing      IP Spoofing
    Protection        Protection

อย่างไรก็ตาม Network Security ไม่ควรพึ่ง Feature เหล่านี้เพียงอย่างเดียว แต่ควรทำงานร่วมกับ VLAN, ACL, Firewall, 802.1X, Endpoint Security และ Monitoring ตามหลัก Defense in Depth

หลังจากเข้าใจ DHCP Snooping, DAI และ IP Source Guard แล้ว หัวข้อถัดไปที่เหมาะสมคือ Port Security และ 802.1X บน Cisco Switch: ควบคุมอุปกรณ์และผู้ใช้ที่เชื่อมต่อ Network

Share this
Facebook Share X
TECHEREST COMMUNITY

Share your thoughts here

Join the conversation and share your perspective on this article.

Comments will load when you reach this section.