RE: [fw-wiz] VLAN Security

From: John Kougoulos (koug_at_intranet.gr)
Date: 06/10/04

  • Next message: Carson Gaspar: "RE: [fw-wiz] VLAN Security"
    To: "DCSIM Subscriptions (IA)" <DCSIMSUBS@ia.ngb.army.mil>
    Date: Thu, 10 Jun 2004 19:41:24 +0300 (EEST)
    
    

    > * Never deliver VLAN 1 downstream (switchport trunk allowed vlan remove 1)

    Is this possible? As far as I know you can not remove vlan 1 from a trunk
    at least on a cisco switch. Even if it doesn't appear on the allowed
    vlans, if you put a sniffer you will see traffic from vlan 1 and on show
    spanning-tree you will see it running an STP instance for vlan 1.

    Regards,

    John

    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


  • Next message: Carson Gaspar: "RE: [fw-wiz] VLAN Security"

    Relevant Pages

    • Re: Separating networks
      ... I'm not talking about the user machine selecting a VLAN, ... about the cisco switch *assigning* the user machine to a VLAN that it ... A router is a little more secure than a switch, ...
      (microsoft.public.security)
    • RE: [fw-wiz] VLAN Security
      ... As far as I know you can not remove vlan 1 from a trunk ... > at least on a cisco switch. ... I believe this was fixed in recent versions of the switch software (as we ...
      (Firewall-Wizards)
    • Re: IAS and dynamic vlans
      ... IAS can do this. ... Maybe based on the AD group membership, ... Tunnel-Type -> VLAN ... And on your cisco switch you will only have to add one additional ...
      (microsoft.public.internet.radius)
    • Re: how to configure voice vlan on cisco 3500?
      ... I'm trying to setup voice vlan on my cisco switch so that my ...
      (comp.dcom.sys.cisco)
    • Creating VLANS on 6500 IOS 12.2
      ... I have done VLANs on IOS 12.0 on Cisco switch like a 3524XL, ... How do you just create a basic VLAN for a few ports so the devices in ... When I provision a port with its own public IP subnet, ... so they want me to give them two ports of the ...
      (comp.dcom.sys.cisco)