Re: HP BL30's and VLAN's

From: jkowall (jkowall_at_shocking.net)
Date: 03/04/05

  • Next message: Dan Rogers: "Testing large networks"
    Date: Fri, 04 Mar 2005 12:10:36 -0500
    To: Michael Sierchio <kudzu@tenebras.com>
    
    
    

    You can arp spoof any switch that is misconfigured. You can gain a span
    port on seperated switches as well, its just 2 spans versus one.

    Having proper IDS and monitoring is the only way to detect and prevent
    this stuff.

    Michael Sierchio wrote:

    > jkowall wrote:
    >
    >> VLANs are just as secure as different switches.
    >
    >
    > I beg to differ. It is possible to gain a spanning port on a
    > VLAN switch, either through the normal mechanism or by overloading
    > the MAC db.
    >
    > Even under normal operation, you won't be getting the same
    > degree of traffic separation.
    >
    > Regards,
    >
    > Michael Sierchio

    
    



  • Next message: Dan Rogers: "Testing large networks"

    Relevant Pages

    • RE: SPAN Port
      ... It all depends on the switch you're using. ... SPAN session are the source and destination/monitor ports. ... Subject: SPAN Port ... Planning, Computer Emergency Response Teams, and Digital Investigations. ...
      (Security-Basics)
    • RE: Caching a sniffer
      ... I'm aware of SPAN, of course. ... sniffing, not PREVENT it. ... devices from going into promiscuous mode, or shut down the switch ... > It's called Port Mirroring or SPAN. ...
      (Security-Basics)
    • Re: Cat 2924
      ... Copyright 1986-2004 by cisco Systems, ... BOX in both H/W and S/W, compared to a C2924-XL Switch... ... FastEthernet0/1 failed front-end loopback test ... to make the port configuration "visible", you need to apply 2 commands ...
      (comp.dcom.sys.cisco)
    • Re: Cat 2924
      ... Copyright 1986-2004 by cisco Systems, ... BOX in both H/W and S/W, compared to a C2924-XL Switch... ... FastEthernet0/1 failed front-end loopback test ... to make the port configuration "visible", you need to apply 2 commands ...
      (comp.dcom.sys.cisco)
    • Gigabit Flexibility with Magnum 6K32T Managed Switch from GarrettCom, Inc.
      ... THROUGHPUT WITH MAGNUM 6K32T MANAGED SWITCH ... Gigabit port capability to four Gb ports when compared to the ...
      (comp.dcom.lans.ethernet)