หลังจากทำความเข้าใจ DHCP Snooping และ Dynamic ARP Inspection (DAI) แล้ว Security Feature ลำดับต่อไปที่ควรรู้จักคือ IP Source Guard หรือ IPSG ซึ่งช่วยควบคุม Source IP Traffic ที่เข้าสู่ Cisco Switch ผ่าน Access Port
IP Source Guard สามารถนำข้อมูลจาก DHCP Snooping Binding Database มาใช้สร้างเงื่อนไขสำหรับตรวจสอบ Traffic ว่าต้นทางสอดคล้องกับ IP Address, MAC Address, VLAN และ Interface ที่ Switch เรียนรู้ไว้หรือไม่ ตามความสามารถและ Configuration ของ Platform
แนวคิดนี้ช่วยลดความเสี่ยงจาก IP Spoofing ซึ่งเป็นกรณีที่อุปกรณ์ส่ง Packet โดยใช้ Source IP Address ที่ไม่ควรถูกใช้งานจาก Port นั้น
สารบัญ
- IP Spoofing คืออะไร?
- IP Spoofing มีความเสี่ยงอย่างไร?
- IP Source Guard คืออะไร?
- IPSG กับ DHCP Snooping Binding
- IP Source Guard ทำงานอย่างไร?
- ตั้งค่า IP Source Guard บน Cisco Switch
- ตรวจสอบ IP และ MAC Address
- Static IP ต้องทำอย่างไร?
- DHCP Snooping + DAI + IPSG
- Troubleshooting
- Cisco Lab
- คำสั่ง Cisco ที่ควรรู้
- FAQ
ภาค 1: ทำความเข้าใจ IP Spoofing
IP Spoofing คืออะไร?
IP Spoofing คือการสร้างหรือส่ง IP Packet โดยกำหนด Source IP Address ให้เป็น Address อื่น แทนที่จะใช้ Source IP ที่ควรถูกใช้โดยอุปกรณ์นั้น
ตัวอย่างเชิงแนวคิด:
PC-A
IP จริง
192.168.10.100
แต่ส่ง Packet โดยใช้
Source IP
192.168.10.50
Switch Layer 2 แบบพื้นฐาน ไม่ได้ตัดสินใจ Forward Frame จาก Source IP Address แต่ใช้ข้อมูล Layer 2 เช่น MAC Address และ VLAN
ดังนั้นหากไม่มี Security Control เพิ่มเติม Switch อาจไม่ได้ตรวจสอบว่า Source IP Address ใน Packet เหมาะสมกับ Access Port นั้นหรือไม่
IP Spoofing มีความเสี่ยงอย่างไร?
การปลอม Source IP สามารถเกี่ยวข้องกับปัญหาหลายประเภท เช่น:
- การปลอมตัวเป็น IP Address ของอุปกรณ์อื่น
- การหลีกเลี่ยง Policy ที่พึ่งพา Source IP เพียงอย่างเดียว
- การสร้าง Traffic ที่มี Source Address ไม่ถูกต้อง
- การรบกวนการทำงานของ Network
- ทำให้ Logging และ Troubleshooting ซับซ้อนขึ้น
ภาค 2: IP Source Guard
IP Source Guard คืออะไร?
IP Source Guard — IPSG เป็น Layer 2 Security Feature บน Cisco Switch ที่รองรับ ซึ่งช่วยจำกัด Source IP Traffic ที่สามารถเข้าสู่ Network ผ่าน Layer 2 Port
แนวคิดพื้นฐาน:
Client
|
| IP Packet
v
Access Port
|
v
IP Source Guard
|
+---- Valid Source ----> Forward
|
+---- Invalid Source --> Drop
IPSG สามารถใช้ข้อมูลจาก DHCP Snooping Binding Database เพื่อสร้าง Source Binding สำหรับ Client ที่ได้รับ IP ผ่าน DHCP
IP Source Guard กับ DHCP Snooping Binding
จากบทความ DHCP Snooping Switch สามารถเรียนรู้ข้อมูล เช่น:
MAC Address IP Address VLAN Interface
----------------------------------------------------
AAAA.AAAA.AAAA 192.168.10.101 10 Gi1/0/5
BBBB.BBBB.BBBB 192.168.10.102 10 Gi1/0/6
ข้อมูลนี้ทำให้ Switch ทราบว่า:
Gi1/0/5
|
+-- VLAN 10
|
+-- IP 192.168.10.101
|
+-- MAC AAAA.AAAA.AAAA
เมื่อเปิด IP Source Guard บน Gi1/0/5 Switch สามารถนำ Binding มาใช้สร้าง Source Filter เพื่อควบคุม Traffic จาก Port ดังกล่าว
IP Source Guard ทำงานอย่างไร?
ลำดับการทำงานเชิงแนวคิด:
Client
|
| DHCP Request
v
Cisco Switch
|
v
DHCP Snooping
|
v
DHCP Transaction Valid
|
v
Binding Database
|
+-- IP
+-- MAC
+-- VLAN
+-- Interface
|
v
IP Source Guard
|
v
Source Filter
|
+---- Match ----> Forward
|
+---- No Match -> Drop
ดังนั้น DHCP Snooping ไม่ได้มีหน้าที่เพียงป้องกัน Rogue DHCP Server แต่ยังสร้างฐานข้อมูล ที่ Security Feature อื่นสามารถนำไปใช้ต่อได้
ตั้งค่า IP Source Guard บน Cisco Switch
สมมติ Network:
VLAN 10 = USERS
Gi1/0/1 - 20
Client Access Ports
Gi1/0/24
Trusted DHCP Path
Step 1 — เปิด DHCP Snooping
Switch# configure terminal
Switch(config)# ip dhcp snooping
Switch(config)# ip dhcp snooping vlan 10
Step 2 — กำหนด DHCP Snooping Trusted Port
สมมติ Gi1/0/24 เป็นเส้นทางที่ DHCP Server Responses เข้ามา:
Switch(config)# interface gigabitEthernet 1/0/24
Switch(config-if)# ip dhcp snooping trust
Switch(config-if)# exit
Step 3 — ตรวจสอบ DHCP Binding
Switch# show ip dhcp snooping binding
ก่อนเปิด IPSG ควรตรวจสอบว่า Client ได้รับ DHCP Lease และ Binding Database มีข้อมูลถูกต้อง
Step 4 — เปิด IP Source Guard
บน Access Port ที่รองรับ สามารถใช้:
Switch(config)# interface gigabitEthernet 1/0/5
Switch(config-if)# ip verify source
Switch(config-if)# exit
จากนั้น Switch สามารถสร้าง Source Filtering Information จาก Binding ที่เกี่ยวข้อง ตาม Platform และ Configuration
ip verify source
บน Production Access Port
ก่อนตรวจสอบ DHCP Snooping Binding
และ Static IP Devices
เพราะ Client ที่ไม่มี Binding
ที่ระบบยอมรับอาจถูก Block
IP Source Guard ตรวจสอบ MAC Address ได้หรือไม่?
Cisco Platform บางรุ่นรองรับ Source IP และ Source MAC Verification เพิ่มเติม
ตัวอย่าง Syntax ที่พบในบาง Platform:
Switch(config-if)# ip verify source port-security
แนวคิดคือการตรวจสอบเพิ่มเติมว่า Traffic สอดคล้องกับทั้ง Source IP Binding และ Layer 2 Source MAC Information
Expected Binding
IP
192.168.10.101
MAC
AAAA.AAAA.AAAA
VLAN
10
Port
Gi1/0/5
ip verify source
แตกต่างกันตาม Cisco Switch Model,
IOS/IOS XE Version และ Feature Set
ควรตรวจสอบ Command Reference
ของอุปกรณ์จริงก่อน Configuration
Static IP กับ IP Source Guard
ประเด็นสำคัญเกิดขึ้นเมื่อ Client ไม่ได้รับ IP จาก DHCP แต่กำหนด Static IP ด้วยตนเอง
Printer
|
+-- IP 192.168.10.50
|
+-- Static IP
|
+-- No DHCP Transaction
เมื่อไม่มี DHCP Transaction Switch อาจไม่มี Dynamic DHCP Snooping Binding สำหรับอุปกรณ์นั้น
บน Platform ที่รองรับ สามารถใช้ Static IP Source Binding เพื่อกำหนด Mapping ที่ได้รับอนุญาต
ตัวอย่างแนวคิด:
Switch(config)# ip source binding aaaa.bbbb.cccc vlan 10 192.168.10.50 interface gigabitEthernet 1/0/10
จากนั้นสามารถตรวจสอบ Binding ด้วยคำสั่งที่ Platform รองรับ เช่น:
Switch# show ip source binding
ภาค 3: DHCP Snooping + DAI + IP Source Guard
สาม Security Features ทำงานต่างกันอย่างไร?
ทั้งสาม Feature มีความสัมพันธ์กัน แต่ไม่ได้ทำหน้าที่เหมือนกัน
| Feature | สิ่งที่ตรวจสอบ | ความเสี่ยงที่ช่วยลด |
|---|---|---|
| DHCP Snooping | DHCP Messages | Rogue DHCP Server |
| Dynamic ARP Inspection | ARP Messages | ARP Spoofing / Poisoning |
| IP Source Guard | Source IP Traffic ที่ Access Port | IP Spoofing |
ภาพรวม:
DHCP Client
|
v
+------------------+
| DHCP Snooping |
+------------------+
|
v
Binding Database
|
+--------+--------+
| |
v v
+----------------+ +----------------+
| DAI | | IPSG |
+----------------+ +----------------+
| |
v v
ARP Validation Source IP
Validation
DHCP Snooping
Question:
"DHCP Server Message นี้
มาจาก Port ที่ได้รับอนุญาตหรือไม่?"
Dynamic ARP Inspection
Question:
"ARP Mapping นี้
สอดคล้องกับ Binding
ที่เชื่อถือได้หรือไม่?"
IP Source Guard
Question:
"Source IP นี้
ควรได้รับอนุญาตให้ส่ง Traffic
จาก Port นี้หรือไม่?"
ตัวอย่าง Layer 2 Access Security Architecture
DHCP Server
|
|
Trusted Path
|
+-------------+
| Cisco Switch|
+-------------+
/ | \
/ | \
/ | \
PC-A PC-B PC-C
| | |
+-------+-------+
|
Access / Untrusted
Ports
Security Controls
DHCP Snooping
|
+---- Rogue DHCP Protection
|
+---- Binding Database
|
+--------+--------+
| |
v v
DAI IPSG
| |
v v
ARP Validation Source IP
Validation
หากต้องการเพิ่ม Security สามารถนำ Feature อื่นเข้ามาร่วมด้วย เช่น:
- Port Security
- 802.1X
- VLAN Segmentation
- ACL
- Firewall
- Endpoint Security
- Network Monitoring
แนวทางนี้เรียกว่า Defense in Depth คือไม่พึ่ง Security Control เพียงตัวเดียว
ภาค 4: Troubleshooting IP Source Guard
เปิด IP Source Guard แล้ว Client ใช้งานไม่ได้ ตรวจอะไรบ้าง?
หาก Client ใช้งานได้ก่อนเปิด IPSG แต่ใช้งานไม่ได้หลังเปิด ควรตรวจสอบตามลำดับ
1. ตรวจสอบ Interface
Switch# show interfaces status
2. ตรวจสอบ VLAN
Switch# show vlan brief
3. ตรวจสอบ Switchport
Switch# show interfaces gigabitEthernet 1/0/5 switchport
4. ตรวจสอบ DHCP Snooping
Switch# show ip dhcp snooping
ตรวจสอบว่า DHCP Snooping เปิดบน VLAN ถูกต้อง และ Trusted Path ถูกกำหนดตรงกับ Network Design
5. ตรวจสอบ DHCP Snooping Binding
Switch# show ip dhcp snooping binding
ตรวจสอบว่า Client มี:
- IP Address ถูกต้อง
- MAC Address ถูกต้อง
- VLAN ถูกต้อง
- Interface ถูกต้อง
6. ตรวจสอบ IP Source Binding
Switch# show ip source binding
7. ตรวจสอบ IP Source Guard Configuration
คำสั่งตรวจสอบเฉพาะ อาจแตกต่างตาม Platform จึงควรตรวจสอบ Running Configuration ของ Interface ร่วมด้วย
Switch# show running-config interface gigabitEthernet 1/0/5
8. ตรวจสอบ Client
Windows:
ipconfig /all
หาก Client ใช้ DHCP สามารถทดสอบ Renew Lease:
ipconfig /release
ipconfig /renew
9. ตรวจสอบ Static IP
หาก Client ใช้ Static IP ตรวจสอบว่ามี Static Source Binding หรือ Configuration ที่รองรับ Client ดังกล่าวหรือไม่
10. ตรวจสอบ Log
Switch# show logging
ใช้ตรวจสอบ Event ที่อาจเกี่ยวข้องกับ DHCP Snooping, IPSG, Port Security หรือ Interface State
Cisco Lab: DHCP Snooping + DAI + IP Source Guard
Lab นี้ใช้รวมความรู้จาก สามบทความเข้าด้วยกัน
Topology
DHCP Server
|
|
Gi1/0/24
|
+--------------+
| Cisco Switch |
+--------------+
/ \
/ \
Gi1/0/5 Gi1/0/6
| |
PC-A PC-B
VLAN 10
Step 1 — สร้าง VLAN
Switch(config)# vlan 10
Switch(config-vlan)# name USERS
Switch(config-vlan)# exit
Step 2 — กำหนด Access Ports
Switch(config)# interface range gigabitEthernet 1/0/5 - 6
Switch(config-if-range)# switchport mode access
Switch(config-if-range)# switchport access vlan 10
Switch(config-if-range)# spanning-tree portfast
Switch(config-if-range)# exit
Step 3 — DHCP Snooping
Switch(config)# ip dhcp snooping
Switch(config)# ip dhcp snooping vlan 10
Step 4 — Trust DHCP Server Path
Switch(config)# interface gigabitEthernet 1/0/24
Switch(config-if)# ip dhcp snooping trust
Switch(config-if)# exit
Step 5 — ให้ Client รับ DHCP ก่อน
ตรวจสอบ:
Switch# show ip dhcp snooping binding
ควรเห็น Binding ของ PC-A และ PC-B ก่อนดำเนินการขั้นถัดไป
Step 6 — เปิด DAI
Switch(config)# ip arp inspection vlan 10
หาก Gi1/0/24 เป็น DAI Trusted Infrastructure ตาม Topology:
Switch(config)# interface gigabitEthernet 1/0/24
Switch(config-if)# ip arp inspection trust
Switch(config-if)# exit
Step 7 — เปิด IP Source Guard
Switch(config)# interface range gigabitEthernet 1/0/5 - 6
Switch(config-if-range)# ip verify source
Switch(config-if-range)# exit
Step 8 — ตรวจสอบทั้งหมด
show ip dhcp snooping
show ip dhcp snooping binding
show ip arp inspection
show ip source binding
show mac address-table
Step 9 — ทดสอบ Connectivity
จาก PC:
ipconfig /all
arp -a
ping 192.168.10.1
จากนั้นตรวจสอบว่า IP Address, Gateway และ Binding ตรงกับ Configuration ที่คาดไว้
Step 10 — ทดสอบเฉพาะใน Lab
สามารถเปลี่ยน Static IP ของ Client เป็น Address ที่ไม่มี Binding เพื่อศึกษาพฤติกรรมของ IPSG ใน Lab Environment
คำสั่ง Cisco ที่ควรรู้
| Command | หน้าที่ |
|---|---|
ip dhcp snooping |
เปิด DHCP Snooping |
ip dhcp snooping vlan 10 |
เปิด DHCP Snooping บน VLAN 10 |
ip dhcp snooping trust |
กำหนด DHCP Trusted Interface |
show ip dhcp snooping |
ตรวจสอบ DHCP Snooping |
show ip dhcp snooping binding |
ตรวจสอบ DHCP Snooping Binding |
ip arp inspection vlan 10 |
เปิด Dynamic ARP Inspection |
ip arp inspection trust |
กำหนด DAI Trusted Interface |
show ip arp inspection |
ตรวจสอบ DAI |
ip verify source |
เปิด IP Source Guard บน Interface |
show ip source binding |
ตรวจสอบ IP Source Bindings |
show mac address-table |
ตรวจสอบ MAC Address Table |
show running-config interface ... |
ตรวจสอบ Configuration ของ Interface |
show logging |
ตรวจสอบ System Log |
คำถามที่พบบ่อย — FAQ
IP Source Guard คืออะไร?
IP Source Guard หรือ IPSG เป็น Security Feature ที่ช่วยควบคุม Source IP Traffic ที่เข้าสู่ Cisco Switch ผ่าน Layer 2 Access Port ตาม Source Binding ที่ Switch ใช้อ้างอิง
IP Source Guard ป้องกันอะไร?
IPSG ช่วยลดความเสี่ยงจาก Source IP Spoofing โดยจำกัดว่า Source IP ใด สามารถส่ง Traffic ผ่าน Interface ที่กำหนดได้
IP Source Guard ใช้ข้อมูลจากที่ไหน?
สำหรับ DHCP Client IPSG สามารถใช้ DHCP Snooping Binding Database ซึ่งมีข้อมูลเกี่ยวกับ IP Address, MAC Address, VLAN และ Interface
ต้องเปิด DHCP Snooping ก่อน IP Source Guard หรือไม่?
สำหรับ Dynamic DHCP Bindings DHCP Snooping เป็นองค์ประกอบสำคัญ เพราะสร้าง Binding Database ที่ IPSG สามารถนำไปใช้สร้าง Source Filters
IP Source Guard กับ DAI เหมือนกันหรือไม่?
ไม่เหมือนกัน DAI เน้นตรวจสอบ ARP Messages ส่วน IP Source Guard เน้นตรวจสอบ Source IP Traffic ที่ Access Port
IP Source Guard ใช้กับ Static IP ได้หรือไม่?
สามารถรองรับได้บน Platform และ Configuration ที่เหมาะสม แต่ Static Client ไม่มี Dynamic DHCP Binding จึงอาจต้องกำหนด Static IP Source Binding หรือกลไกอื่นที่ Platform รองรับ
IP Source Guard ใช้แทน Port Security ได้หรือไม่?
ไม่ได้โดยตรง IPSG และ Port Security ควบคุมคนละส่วนของ Access Layer Security และสามารถนำมาใช้ร่วมกัน ตาม Network Design
IP Source Guard ใช้แทน Firewall ได้หรือไม่?
ไม่ได้ IPSG เป็น Access Layer Security Control สำหรับ Source Validation ไม่ได้ทำหน้าที่แทน Stateful Firewall, Application Security หรือ Security Policy ระหว่าง Network Zones
สรุป
IP Source Guard — IPSG เป็น Layer 2 Security Feature ที่ช่วยควบคุม Source IP Traffic จาก Access Port และลดความเสี่ยงจาก IP Spoofing
สำหรับ DHCP Client IPSG สามารถใช้ข้อมูลจาก DHCP Snooping Binding Database เพื่อทราบความสัมพันธ์ระหว่าง IP Address, MAC Address, VLAN และ Interface
เมื่อมองร่วมกับบทความก่อนหน้า จะเห็น Layer 2 Security Chain ชัดเจน:
DHCP Snooping
|
+---- ป้องกัน Rogue DHCP
|
+---- สร้าง Binding Database
|
+-------+-------+
| |
v v
DAI IPSG
| |
v v
ARP Spoofing IP Spoofing
Protection Protection
อย่างไรก็ตาม Network Security ไม่ควรพึ่ง Feature เหล่านี้เพียงอย่างเดียว แต่ควรทำงานร่วมกับ VLAN, ACL, Firewall, 802.1X, Endpoint Security และ Monitoring ตามหลัก Defense in Depth
หลังจากเข้าใจ DHCP Snooping, DAI และ IP Source Guard แล้ว หัวข้อถัดไปที่เหมาะสมคือ Port Security และ 802.1X บน Cisco Switch: ควบคุมอุปกรณ์และผู้ใช้ที่เชื่อมต่อ Network
Share your thoughts here
Join the conversation and share your perspective on this article.