Layer 2 Security

Port Security  : Limits the number of MAC address to be learned on an access switch port.
BPDU guard   : If BPDUs show up where they should not, the switch protects itself.
Root guard     : Control which ports are not allowed to become root ports to remote root switches.
802.1x              : Authentication users before allowing their data frames into the network.
IP source guard  : Prevents spoofing of Layer 3 information by hosts.
DHCP snooping : Prevents rogue DHCP servers from impacting the network.
Storm control     : Limits the amount of broadcast or multicast traffic flowing through the switch.
Dynamic ARP inspection : Prevents spoofing of Layer 2 information by hosts.
Access control lists          : Traffic control to enforce policy.

