MITM & Layer 2 Defense Sandbox

Internal corporate segment 10.0.1.0/24 · ARP spoofing, port security, DAI and 802.1X NAC

● SEGMENT CLEAN Open Lab Guide

Attack Simulation Engine

Controls

Interception / Packet Manipulation Engine

IP Forwarding Kernel[ DISABLED ]
Poisoning modeNONE

No frames intercepted. Trigger bidirectional ARP poisoning, then send HTTP traffic.

Port 1Port 2 · VLAN 10 [Corporate]Port 24 (Uplink)RADIUS / 802.1X
Victim Workstation
Node 1 · Port 1
IP 10.0.1.10
MAC 00:11:22:33:44:10
VLAN 10 [Corporate]
Attacker Device
Node 3 · Port 2 · UP
IP 10.0.1.99
MAC DE:AD:BE:EF:99:99
VLAN 10 [Corporate]
Managed L2 Access Switch
Node 2 · Catalyst-Sim
Port 1 → Victim
Port 2 → Attacker [up]
Port 24 → Uplink [open]
DAI OFF · NAC OFF
Gateway Router
Node 4 · Port 24
IP 10.0.1.1
MAC 00:00:0C:07:AC:01
Default gateway
NAC Controller
Node 5 · 802.1X / RADIUS
Policy engine MONITOR
Binding DB: DHCP snooping
Quarantine VLAN 666 · Guest 99

Inspection Log & Event Feed

Idle. Select a scenario and run the simulation to trace ARP updates, 802.1X events and switch port state changes.

Defense & Remediation

switchport port-security on Gi0/24

Pins the uplink to the gateway MAC address.

Uplink hardening stops a MITM relay from forwarding spoofed frames upstream, but it cannot prevent the poisoning itself on an access port.