Single point problem of DHCP security feature

My network topo is attached.Pls see it.
There is two DHCP server connected to different core switch. Suppose PC1 get IP address from DHCP-SERVER-2,so only 4510-2 learn this and store it on DHCP snooping binding table.
So question is: If I enable ARP inspection on both 4510 and 4510-2 get problem, pc will lose connectivity because 4510-1 didn't learn the IP-MAC information.
I know that "ip arp inspection trust" under interface will work. But my access switch don't support ip arp inspection, for example, 2950. If I add "ip arp inspection trust" under interface connected switch will leave a security hole . Or I can define an ARP ACL . But there are so many PC on my network.
So I am in doubt why cisco can't synchronize DHCP snooping binding table between switch. If cisco can synchronize DHCP snooping binding table , it is a easy solution for me.
thanks!

henry,
you are indeed correct, only other solution would be to manually update dhcp binding file on 4510-1 or create ARP access-list either way would be a pain. You can also consider port-security on switchports of 3500XL.

Similar Messages

  • Securing single point of entry doc-lit web services

    I am designing doc-lit web services with a single point of entry, but the doc can contain requests of various types, with varying levels of authorization on the 'methods' being called by the web service as a result of the passed requests. I'm looking for a standards-compliant means of accomplishing this, or at least some method that will not be insanely difficult to move to a standards-based security implementation when they become available. I do not want to use SSL/TLS, but do want to stick to standards including WS-Security, XML-Encryption and XML-DSig. I would also like to use OID/SSO with certificate-based authentication.
    What are my options as far as existing tools, techniques, etc for this in a Java/Oracle environment? Is there anything in Oracle BPEL that could help me in this quest?
    Appreciate any advice, pointers, shared experiences, etc on this - I'm a little lost in the trees right now!
    Thanks Much,
    Jim Stoll

    Eric - appreciate the tip. The link to the JDev files for the OBE article doesn't work though (ie, in the article, there is a link to download the source for the project) - is there an alternate way that I could get hold of that code? Even something as simple as someone emailing it to me would work - I desperately need to move forward on this stuff. (There's another sample at http://www.oracle.com/technology/products/jdev/101/howtos/securews/index.html, but that one throws exceptions and I can't seem to get any help on it via the forum or Oracle Support, either...)
    Thanks for your assistance!
    Jim

  • "Read Single Point" Keithley 2400 Problems

    Hello!
    I am recentely having some problems with the "Read Single Point Measurements" function in Labview 2012. I have already sucessfully used my Keithley 2400 in other programs to sweep the voltage, but now I am trying to use it also to read the current across my sample. 
    I wrote a very simple program, which resemble the one you can find among Labview examples (see 1st attachment). The only differences are a sweep-subVI and a "for" cycle. My problem occurs at the "Read" Keithley function. On the Keithley's screen I have the following errors:
    - 113 : undefined header;
    - 230: data corrupt or stale;
    - 420: query unterminated.
    While in the Block diagram, when the system gets to the "read" function, the error -1074000000 shows up.
    I have found a lot of posts on this topic, but unfortunately I could not find the any solution for me. I also tried the 2nd attached program, to check the comunication to the instrument, but errors still occur. In "Measurements and Automatic", it says that the instrument is working properly. 
    Do you have any ideas?
    Thanks  
    Attachments:
    Keithley 24XX Sweep and Acquire Measurements.vi ‏26 KB
    Basic Serial Write and Read (1).vi ‏26 KB

    The following video demonstrates how to check the firmware revision: http://www.keithley.nl/centralized_display?mn=2400&assetid=55934.
    In order to update the firmware you will be need to download a flash program and the firmware file. gAfter obtaining the Flash program and the Firmware file from Keithley Application support staff, unzip the three files in a folder of your choice and run the "setup.exe" program.  Follow the instructions to install the program.  When the installation is complete, launch the program from your Windows Start menu under Programs/Keithley Instruments. The Application support staff will also provide the file for the latest firmware revision. Put that file in a folder where you can find it and then run the Flash Wizard32 program. The program will autodetect the instrument and request to specify the firmware file.
    This link contains the flash program: http://www.keithley.com/base_download?dassetid=52609
     See attactment for the firmware revision.
    Attachments:
    2400c30.zip ‏358 KB

  • Security features in AA Pro & Acrobat Reader problem

    Hi,
    In Adobe Acrobat Pro my PDF is shown to have "no security" - everything is allowed.
    When I open that saved documnet in Reader 9.4 it has security features I did not put there.
    In particular, no adding of comments (and markups).
    Any ideas how to resolve problem welcome.

    Thanks Graffiti,
    There seems no problem with the AA pro - opening advanced features - under security properties everything is allowed.
    The problem is that when I open that same PDF in Acrobat Reader (which has no "Advanced") it does nlot allow the adding of comments.
    In Acrobat Reader on toolbar under Document > Security > Show Security Properties : Security : Document Restrictions Summary : under Commenting it is marked : Not Allowed.
    Any idea how to get around this.
    What I want to do is to be able to make PDFs and send then to someone else for adding comments but Reader does not allow this and I am not disabling it when I make the PDF with AA Pro.
    Cheers

  • PROBLEMS SETTING UP REPORTS SECURITY FEATURE

    1. Trying to follow instructions to set up the Reports Security Feature.
    2. Successfully run the script rwwwvins.sql
    3.Hitting following Error
    " Missing string(reports_security_desc) language(us) domain (wwc)sub_domain
    (sec)
    The portlets have similar names.
    The pageORACLE_REPORTS_SECURITY has a display name of :
    Missingstring(reports_security_desc) language(us) domain (wwc) sub_domain
    (sec)"
    4. Followed note 132625.1 with no joy. Same error.
    Any help ?
    null

    do you mean to say that you cannot enter any passphrase on the router web ui or on the wireless computer itself ??
    if its on the router , then upgrade / reflash the router's firmware...

  • Problem due to Ironport Data Security feature

    We are using S160 (version 6.0.1-006) in forward mode and as soon as we enable Ironport Data Security feature the WSA stops responding after some time for few minutes and then starts processing http requests. This happens after every 5-10 mins. and ultimately we have to disable the Data security feature. Once the feature is disabled the WSA works smoothly. Please help......

    Hi,
    If you haven't already, I suggest opening a ticket with customer support.
    Jennie

  • I purchased an iphone 4s secondhand but now i find that the person has a security feature still locked onto the phone and they are not responding to my message. Is there any way to resolve this problem.

    How do I resolve an issue with a secondhand phone purchase that has a security feature link to it and it hasnt been removed therefore I cant use the phone.

    Hi paisley,
    Sorry, there is no way around the Activation Lock. You either need to contact the original owner and get them to turn off Find My iPhone and wipe the phone from their iCloud account, or you need to return it to the seller.
    Sorry,
    GB

  • WAP321 2 SSIDs not both showing Clustered in Single Point Setup

    I have 2 Cisco WAP321 with 2 SSIDs setup Single point using VLAN 1 and VLAN 2 using firmware version 1.0.5.3.  VLAN 1 is the management VLAN.  One WAP321 is connected to a SG200-8 version 1.0.8.3 on a trunked port 1UP,2T.  The SG200-8 is connected to a SG300-28 L3 switch version 1.3.7.18 on a trunk port 1UP,2T.   The other WAP321 is connected to a trunked port 1UP,2T on the SG300-28 switch.  Both SSIDs seem to work but the VLAN2 SSID does not show as clustered under single point Wireless Neighborhood.  Only VLAN1 shows clustered.  Do I have a setup issue? Is the Wireless Neighborhood not showing correct? What do you think is the problem why they are not showing clustered?  Both SSIDs work and connect to the internet.
    PS
    If it matters DHCP is from the SG300-28 in L3 mode which feeds a RV180 router from a 1UP port on the SG300-28.

    My name Eric Moyers. I am an Engineer in the Small Business Support Center.
    You do not have a setup issue. Clustering/Single Point Setup is based on the device and not on the SSID's. When looking at the Wireless Neighborhood within the Clustering section, you will only see the first SSID listed regardless of how many SSID's you have configured. 
    Now as far as the connection are concerned you said that your friends were having a hard time connecting. When they eventually connected were they going to the guest network? When you connect with your laptop, are you connecting to the same SSID or a different one?
    Eric Moyers
    .:|:.:|:. CISCO | Cisco Presales Technical Support | Wireless Subject Matter Expert
    Please rate helpful Posts and Let others know when your Question has been answered.

  • Forms 10g 2 ApplicationServers Single Point of Failure

    Hi,
    we are planning a migration from Forms6i to Forms10g and we are thinking about eliminating as much as possible a single point of failure.
    Today we have all those Clients running Forms-Runtime with the FMBs ...
    They all create a connection against the Database which we have secured as much as possible against Loss of Service.
    After the migration we will have all those Clients running a browser and calling a URL which point to the Application-Server(s) running the Forms-Runtime processes. If this machine fails, none of the Clients can work anymore. Because of that, we are planning for 2 AS to be on a safer side for a Loss of one Server.
    But here starts the question :
    When a clients starts, he will point to an URL which lead to an IP-Address.
    The IP-Address could be of a Hardware-Loadbalancer, if so the LB will forward to Oracle Webcache on one of the AS. If not, The IP-Address leads directly to one Webcache.
    From there it proceeds to the HTTP-Server on one of the AS and then further to the MOD-OC4J Instance, which could be duplicated as well.
    All those "Instances" : Hardware-Loadbalancer, Webcache, HTTP-Server, MOD-OC4J-Instances can be doubled or more but that only makes sense if they run on different hardware, which means different IP-Addresses. I can imagine using a virtual IP-Address for connecting to the HLB or the Webcache but where is it split to the different real addresses with having one Box as a single point of failure.
    I'm looking for a solution to double the ApplicationServer as easy as possible but without having the Clients to decide on which Server they can work and without having a single box in front which would lead to a S.P.O.F.
    I know, that there are HLBs out there which can act as a Cluster so that should eliminate the problem, but I would like to know, whether that cann be done on the AS only.
    Thanks,
    Mark

    Thanks wilfred,
    yes I've read that manual. Probably not every single page ;-)
    I agree that High-Availability is a very broad and complex topic, but my question is (although it was difficult to explain what i mean) only on a small part of it:
    I understand that I can have mutiple instances on each level OC4J, HTTP, WEB-Cache, LBR But where or who excepts one single URL and leads the requests to the available AS
    As mentioned in my post before, we may etst the Microsoft NLB-Cluster to divide the requests to the WEB-Cache Instances on the 2 AS and then the 2 Web-Cache proceed to the 2 HTTP and so on.
    The Idea of that is that Windows offers a virtual IP-Adress from those 2 Windows-Server and somehow the requests will be transferred to a running WEB-Cache.
    Does that work correctly with session-Binding ...
    We'll see
    thanks,
    Mark

  • On startup I get an Alert dialog that tells me that some security feature is not working and I should correct things in the Firefox profile. What's going on?

    On Mac OS X 10.6.6, MacBook Pro.
    When I launch Firefox I get an Alert that says,
    Could not initialize the application's security component. The most likely cause is problems with files in your application's profile directory. Please check that this directory has no read/write restrictions and your hard disk is not full or close to full. It is recommended that you exit the application and fix the problem. If you continue to use this session, you might see incorrect application behaviour when accessing security features.
    If I click OK, it goes away and Firefox seems to work fine, but I don't like this situation. Anyone know what this is?
    I've trashed the old Firefox (which left a few dynamic libs open and I had to restart to empty the trash) and I installed the latest Firefox (3.6.14), but the problem remains. I found a profile for Firefox in the /Library/Cache folder, but I don't know what to do with it. My disk has plenty of room.
    Any help or pointers appreciated

    There are a few possible causes of that error, for details on fixing it see https://support.mozilla.com/kb/Could+not+initialize+the+browser+security+component

  • Why can't we have a single point of contact who de...

    Three weeks ago our house was hit by lightning and our broadband connection went on the blitz (a Linnit technical term).
    The telephone stopped working. I did an on-line check and the connection registered a fault. The on-line system logged the fault with the teachnical team. So far so good...
    I received a call from the tech team advising an engineer was coming out to us, if the fault was with our equipment we would be charged. That's fair. Engineer called. My phones were fine, BUT the BT router was where the fault lay said the engineer. We would need to raise another fault report because he only dealt with telephone AND as he was a subcontractor he would bill for the work... He disconnected the router so the phone would work and left.
    I work virtually, which means that I can work from my home, so I need the internet even more than my family want the telephone. I plugged the internet back in so that I could continue to work and called BT again from my mobile. Speaking to a very polite guy in Delhi I was asked to describe my phone socket, unplug the router from the office, carry it downstairs to the kitchen where the main socket is, plug the router in there, reconnect, try again, all sorts of stuff before finally being advised that it was probably just the 'microfilter' and that as they were very inexpensive it might be faster for me to go out and buy one and plug it in myself rather than have another engineer come out to us.
    So I did just that. In fact, as the microfilters are less than a fiver, I got two... brought them home and plugged one in... didn't work.
    Called Delhi again. Spoke to someone else who was, again, very polite. They tried to get me to unplug and plug things in and out again, but I politely declined this time explaining that now the poor internet connection that we did have was running so slowly I am having to commute in to work over Christmas. He sympathised and told us that he would escalate the issue. That was before Christmas. Since then I received a text on my phone on Christmas Day telling me they couldn't reach me!!! 
    Today I called again to BEG someone to please come out and fix things for us. We aren't technical. We cannot act as pseudo engineers. We pay BT one bill each quarter for a service. Why on earth can't BT provide me with a single point of contact when I have an issue. And if that point of contact could understand me and explain things to me in words and phrases that I understand that would be perfect!
    Last year I cancelled three mobile contracts that we'd had since the early 90's with O2 because they were so unhelpful.
    BT aren't the cheapest broadband provider but we've stayed with them out of 20+ years loyalty and the understanding that we had a one-stop-shop. Now, it looks as though I'll be shopping around for another domestic broadband provider for 2012.

    Thank you for being so helpful and constructive.
    I tried to look at the ASDL settings, john46 but it's asking me for my HomeHub password... the only password I have is for our wireless network and that one doesn't work. 
    I can't test the phone line right now because I'll have to disconnect the internet and I'm currently working on another computer whilst chatting on this one with you. However I will do that later. I'll also look at the RogerB link you provided. 
    Truth is, we're pensioners who use the internet but we havent a grain of technical understanding between us. We're old fashioned enough to admit that we just want someone who knows what he's doing to come here and fix it for us. It's already cost us £130 for an engineer to come out from OpenReach to tell us the phone line is OK and it's the router causing the problem. Best case scenario is that another BT engineer who knows about broadband comes out and does it because the last BT person that I spoke to in Delhi did actually confirm that there is a fault on the BT side. I'm getting so frustrated right now I'll probably call out an independant I find in Yellow Pages and get charged an arm and a leg again and I'll then cancel with BT in a fit of pique.

  • When I start iTunes on my home computer (Not a MAC), it automatically shuts down, and gives me the message that the Data Execution Prevention security feature has shut it down...what to do?

    When I start iTunes on my home computer (Not a MAC), it automatically shuts down, and gives me the message that the Data Execution Prevention security feature has shut it down...what to do?

    For general advice see Troubleshooting issues with iTunes for Windows updates.
    The steps in the second box are a guide to removing everything related to iTunes and then rebuilding it, which is often a good starting point unless the symptoms indicate a more specific approach. Review the other boxes and the list of support documents further down page in case one of them applies.
    Your library should be unaffected by these steps but there is backup and recovery advice elsewhere in the user tip.
    tt2

  • Saving to PDF using VBA in Excel 2007 using security features such as password and print restriction

    Good Afternoon,
    I am wondering if there is a way to implement the security features such as password and print restriction while saving a document to PDF using VBA in Excel 2007. 
    Regards,
    Steve

    Bill,
    Thank you.  I was able to find the security setting section.  The problem I have now, however, is writing the VBA to save to PDF and incorporate the security settings.  I thought if i applied the settings to the Excel document I was working on it would carry over, but this does not seem to be the case.  Any idea's?
    Regards,
    Steve

  • EBay does not recognize new security feature requiring security number in Firefox but works with IE

    eBay has a new security feature when attempting to e-mail a seller; it requires that you enter a numerical code in a box. When on Firefox eBay does not recognize that I've entered the number and keeps telling me to enter the number but when on IE it recognizes the number. What add-on, etc do I need to make Firefox compatible with eBay? Thanks
    == URL of affected sites ==
    http://ebay.com

    The problem seems to be caused by the Java Console add-ons. Disabling mine (6.0.20 and 6.0.21) fixed the problem.

  • How can I design Load Balancing for distant Datacenters? without single point of failure

    Dear Experts,
    We are using the following very old and passive method of redundancy for our cload SaaS but it's time to make it approperiate. Can youplease advise:
    Current issues:
    1. No load balancing. IP selection is based on primary and secondary IP configurations. If Primary fails to respond, IP record for DNS changes to secondary IP with TTL=1min
    2. When primary server fails, it takes around 15 min for clients to access the servers. Way too long!
    The target:
    A. Activate a load balancing mechanism to utilized the stand-by server.
    B. How can the solution be designed to avoid single point of failure? In the previous example, UltraDNS is a single point of failure.
    C. If using GSS is the solution, how can it be designed in both server locations (for active redundancy) using ordinary DNS server?
    D. How can HSRP, GSS, GSLB, and/or VIP be used? What would be the best solution?
    Servers are running ORACLE DB, MS SQL, and tomcat with 2x SAN of 64TB each.

    Hi Codlick,
    the answer is, you cannot (switch to two web dispatchers).
    If you want to use two web dispatchers, they need something in front, like a hardware load balancer. This would actually work, as WD know their sessions and sticky servers for those. But remember you always need a single point for the incoming address (ip).
    Your problem really is about switchover groups. Both WD need to run in different switchover groups and need to switch to the same third software. I'm not sure if your switchover software can handle this (I'm not even sure if anyone can do this...), as this means the third WD needs to be in two switchover groups at the same time.
    Hope this helps,
    Regards,
    Benny

Maybe you are looking for

  • To maintain UTF-16 characters from a file

    Hello, I have a text-file that includes some special characters (UTF-16), I must write a java class that modifies the text, maintaining these special characters. I try with: in = new BufferedReader(new InputStreamReader( new FileInputStream("PapersVe

  • Problem whith JDeveloper 11g to startup EJB Client

    When i Run the EJBBean display this error message: 1/02/2008 10:03:54 AM oracle.j2ee.xml.XMLMessages warningException ADVERTENCIA: Exception Encountered 1/02/2008 10:03:55 AM oracle.oc4j.util.SystemLog log GRAVE: Server start failed processing config

  • Precompiling JSPs changes directory name

    I am using the weblogic.appc compiler to precompile JSPs and I noticed that if my source folder name contains a hyphen, eg. my-test, after precompilation the class files are stored under \WEB-INF\classes\jsp_servlet\_my_45_test\ directory.           

  • Stock Locked in transaction LT10

    Hi All, I am having a problem confirming a pick TO. The error message I am getting is zero cases are available. Where as there is stock available in the pick (and also the TO creation went fine) When I display the stock in pick using LT10 I see a loc

  • Updating Java for my 10.4.11. It tells me that i need to free up space on my start up disk. Can anyone talk me through this.

    Hi all.. Ive had my mac for quite some time, could say its been abused.. brought 2nd hand. But i do love it!!! I dont know a great deal about the software. Im trying to update my Java but while doing so it tells me that i need to free up space on my