Re: [fw-wiz] Firewalls and 802.1q trunking

From: David Pick (d.m.pick@qmul.ac.uk)
Date: 11/27/02


To: Steffen Kluge <kluge@fujitsu.com.au>
From: David Pick <d.m.pick@qmul.ac.uk>
Date: Wed Nov 27 08:08:01 2002


> My concern is that the "fan-out" boxes are typically run-of-the-mill
> switches, like Cisco Catalysts, that probably have been design without
> any security aspirations. I wouldn't be surprised if those switches
> could be attacked and tricked into leaking packets between VLANs.

A valid concern. My attitude is simple:
  * If the switches are secure enough to keep VLANs seperated for
    normal traffic then they're secure enough to use as interfaces
    to your firewall
  * If they're not, well, they're not!

-- 
	David Pick


Relevant Pages

  • Re: Hardening Cisco Catalyst Switches
    ... used Cisco Secure ACS for TACACS+ access ... We thought about and tested limiting access to the switches to ... >Does anyone have any suggestions on how to make a secure configuration on a switch? ... >I know about enabling secret password, changing the default SNMP community strings, filtering connections to the switch itself, using ACLs on VLANs etc, but I would appreciate some more good ideas. ...
    (Security-Basics)
  • Re: [fw-wiz] Firewalls and 802.1q trunking
    ... generic secure network design common sense ... I wouldn't be surprised if those switches ...
    (Firewall-Wizards)
  • Re: [fw-wiz] Firewalls and 802.1q trunking
    ... >> any security aspirations. ... I wouldn't be surprised if those switches ... > normal traffic then they're secure enough to use as interfaces ... what about resistance to DOS attacks? ...
    (Firewall-Wizards)
  • Stunnel..
    ... I am trying to secure a mysql connection usning the example provided on ... When I run the commands shown I get the following error.. ... what switches are available and none of the examples I have tried so far ...
    (Fedora)
  • Re: Is VLAN still secure ?
    ... > secure as on different switches fpr diferent Networks. ... > build a DMZ on one Switch with an DMZ VLAN and a Secure VLAN. ... Vlan's are not a security option. ...
    (comp.security.firewalls)