Categories
Welcome Center
Education & Development
Discussions
Certification Preparation
Recent Posts
Groups
Free Resources
Ebooks
Free Workshops
Trending Certifications Infographic
Infosec Training
IT & Security Training
Live Boot Camps
Security Awareness Training
About Infosec Institute
Home
Certification Preparation
EC-Council
Flooding a switch
danc_101
Hello,
I'm trying to flood a Cisco 2950 switch so it falls over to bridge mode.
I'm using Ettercap to flood the switch. I can see all the MAC's in the CAM table have been used up via the show mac-address-table count command (8,000 in total on a 2950)
However when I run Wireshark to start sniffing I cannot see any unicast data between other hosts, I only see multicast frames (i.e. DHCP traffic etc)
Has anyone done this before or have any idea what I'm doing wrong or not doing ?
Thanks
Find more posts tagged with
Save $250 on 2025 certification boot camps from Infosec!
Book now with code EOY2025
Button
Comments
GAngel
Most of the later IOS have broadcast suppression built in. Yours may be enabled.
danc_101
Thanks - I disabled that before I tried the flood but still no joy..
JDMurray
I have a couple of 2900-series switches laying around. This weekend, I'll try using BackTrack 4 to duplicate what you are doing and see if I get the same results. What's the version/date/features of IOS that you are using?
danc_101
Thanks JD - the IOS version is c2950-i6q4l2-mz.121-22.EA1.bin
Quick Links
All Categories
Recent Posts
Activity
Unanswered
Groups
Best Of
INFOSEC Boot Camps
$250
OFF
Use code
EOY2025
to receive $250 off your 2025 certification boot camp!
BROWSE BOOT CAMPS