RE: [fw-wiz] VLAN Security

From: John Kougoulos (koug_at_intranet.gr)
Date: 06/10/04

  • Next message: Carson Gaspar: "RE: [fw-wiz] VLAN Security"
    To: "DCSIM Subscriptions (IA)" <DCSIMSUBS@ia.ngb.army.mil>
    Date: Thu, 10 Jun 2004 19:41:24 +0300 (EEST)
    
    

    > * Never deliver VLAN 1 downstream (switchport trunk allowed vlan remove 1)

    Is this possible? As far as I know you can not remove vlan 1 from a trunk
    at least on a cisco switch. Even if it doesn't appear on the allowed
    vlans, if you put a sniffer you will see traffic from vlan 1 and on show
    spanning-tree you will see it running an STP instance for vlan 1.

    Regards,

    John

    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


  • Next message: Carson Gaspar: "RE: [fw-wiz] VLAN Security"

    Relevant Pages

    • Re: Separating networks
      ... I'm not talking about the user machine selecting a VLAN, ... about the cisco switch *assigning* the user machine to a VLAN that it ... A router is a little more secure than a switch, ...
      (microsoft.public.security)
    • RE: [fw-wiz] VLAN Security
      ... As far as I know you can not remove vlan 1 from a trunk ... > at least on a cisco switch. ... I believe this was fixed in recent versions of the switch software (as we ...
      (Firewall-Wizards)
    • Re: IAS and dynamic vlans
      ... IAS can do this. ... Maybe based on the AD group membership, ... Tunnel-Type -> VLAN ... And on your cisco switch you will only have to add one additional ...
      (microsoft.public.internet.radius)
    • Re: how to configure voice vlan on cisco 3500?
      ... I'm trying to setup voice vlan on my cisco switch so that my ...
      (comp.dcom.sys.cisco)
    • Re: how to configure voice vlan on cisco 3500?
      ... I'm trying to setup voice vlan on my cisco switch so that my ... Since I've never used the smaller switches for auxiliary vlans, ...
      (comp.dcom.sys.cisco)