MITM & Layer 2 Defense Sandbox
Internal corporate segment 10.0.1.0/24 · ARP spoofing, port security, DAI and 802.1X NAC
● SEGMENT CLEAN Open Lab Guide
Attack Simulation Engine
Controls
Interception / Packet Manipulation Engine
IP Forwarding Kernel[ DISABLED ]
Poisoning modeNONE
No frames intercepted. Trigger bidirectional ARP poisoning, then send HTTP traffic.
Victim Workstation
Node 1 · Port 1
IP 10.0.1.10
MAC 00:11:22:33:44:10
VLAN 10 [Corporate]
Attacker Device
Node 3 · Port 2 · UP
IP 10.0.1.99
MAC DE:AD:BE:EF:99:99
VLAN 10 [Corporate]
Managed L2 Access Switch
Node 2 · Catalyst-Sim
Port 1 → Victim
Port 2 → Attacker [up]
Port 24 → Uplink [open]
DAI OFF · NAC OFF
Gateway Router
Node 4 · Port 24
IP 10.0.1.1
MAC 00:00:0C:07:AC:01
Default gateway
NAC Controller
Node 5 · 802.1X / RADIUS
Policy engine MONITOR
Binding DB: DHCP snooping
Quarantine VLAN 666 · Guest 99
Inspection Log & Event Feed
Idle. Select a scenario and run the simulation to trace ARP updates, 802.1X events and switch port state changes.
Defense & Remediation
switchport port-security on Gi0/24
Pins the uplink to the gateway MAC address.
Uplink hardening stops a MITM relay from forwarding spoofed frames upstream, but it cannot prevent the poisoning itself on an access port.