Re: RE: IPS and Trunking



Yes I agree that most of the product supports VLAN dot 1Q but important thing is if they can do so in IPS mode specially when the IPS is configured in Layer 2 mode or transparent mode.
I know of Juniper ISG platform not supporting VLAN in layer 2 or transparent mode. VLAN and NAT supported only on Layer 3 mode of juniper ISG platform.

However other products like Fortigate, Proventia, iPolicy Intrusion Prevention firewall and many other products do support VLAN (dot 1Q) with IPS in Layer 2 .

Good thing about iPolicy Intrusion prevention firewall is that it supports NAT as well in Layer2 while Juniper cant.

U want to be absolutely sure of all the details when u are talking to any vendor regarding these kind of features.

Regards,
Vijay Upadhyaya

------------------------------------------------------------------------
Test Your IDS

Is your IDS deployed correctly?
Find out quickly and easily by testing it
with real-world attacks from CORE IMPACT.
Go to http://www.coresecurity.com/index.php5?module=Form&action=impact&campaign=intro_sfw
to learn more.
------------------------------------------------------------------------



Relevant Pages

  • FW: Best VLAN supporting Switch
    ... you must install a router which interconnects each VLAN. ... Layer 3 switches tends to be very costly. ... The switches are about $1200 and the layer 3 module is $1400. ... node network with 200+ cisco switch's using multiple vlan's. ...
    (Security-Basics)
  • RE: Dhcp security
    ... One way "depending on how many clients you are servicing" would be to ... create MAC (layer 2) based reservations, ... MAC reservation). ... aforementioned would be VLAN membership rubbish. ...
    (Focus-Microsoft)
  • Re: VLAN basic question
    ... the same VLAN (EG: all Severs into VLAN 21, ... server than the Sales people, wouldn't you put the Accounts server and ... While I have tons of layer 3 distribution layer stuff in my production ... networks), device management interfaces, wintel, sun, aix, linux, ...
    (comp.dcom.sys.cisco)
  • Re: VLAN across a routed connection?
    ... Port-channels can be layer 2 or 3 - just like physical ports. ... I suggest you change your Port-channel to layer 2 so it can be ... "common VLAN" and the SVI VLAN for routed traffic: ... switchport trunk encapsulation dot1q ...
    (comp.dcom.sys.cisco)
  • RE: VALN hopping
    ... one of the networks allows inbound internet access. ... According to Cisco they are a good security measure. ... I don't know of any exploits which enable you to VLAN hop. ... therefore require a Layer 3 device to route traffic between them. ...
    (Security-Basics)