MAC Flooding Security

Hi Guys

So I’ve been doing pen testing labs on my Mikrotiks. See list of variants below. The one attack which I can’t really find a reliable answer/solution for is “MAC Flooding” on a router network without a switch.

Mikrotiks:

  • CCR1009
  • RB2011
  • RB952 v2
  • RB750Gr3

Pen testing tool: “Macof”

I was considering MAC Limiting per port but can’t seem to find the correct way or actually manage to do it without a switch.
I try not to make use of a AAA server except RouterOS functionality.

Any suggestions, ideas, solutions, brain farts etc are welcome.

I have the same issue, it just kills the memory on my RB5009, I watch my 830Mb free drop to 97Mb and then the device reboots.