RE: VLAN as a DMZ

From: Smith, Chris (csmith@Calence.com)
Date: 03/08/02


From: "Smith, Chris" <csmith@Calence.com>
To: 'Mike Shaw' <mshaw@wwisp.com>, security-basics@securityfocus.com
Date: Fri, 8 Mar 2002 09:08:30 -0700 

VLAN-Hopping is a potential using only VLAN security to isolate an insecure
network segment - a previous version of CatOS code had such a
vulnerability. Another issue is misconfiguration (more likely) - i.e.
placing a trusted host on the VLAN, misconfiguring layer 3 routing, etc.

A better approach is to use a separate switch (off the core) for
DMZ/Extranet/untrusted segments. The potential for compromise exists, but
your risk may be reduced by securing the core devices from compromise. It's
the best blend of $$ vs. Security.

chrisls

-----Original Message-----
From: Mike Shaw [mailto:mshaw@wwisp.com]
Sent: Wednesday, March 06, 2002 1:26 PM
To: security-basics@securityfocus.com
Subject: VLAN as a DMZ

There are definitely textbook reasons (secondary compromize issues, etc),
but does anyone know of a specific technical reason why using a VLAN for a
DMZ segment is a bad idea (cisco 5500 switch)?

The VLAN would have no telnet interface living on it, and no level 3
switching/routing going to/from it. It'd be just an isolated segment. The
only thing I could think of would be that someone could spoof the
frame-tagging or something.

Any input is appreciated.

-Mike



Relevant Pages

  • 1168 octets payload and bad TCP checksums
    ... a vlan switch then terminates the trunked ... segment and splits it into separate physical subnets. ... octets of payload as the checksum is ... it appears only TCP packets with 1168 octets of data are ...
    (freebsd-net)
  • Re: NLBS in VLANs environment
    ... computer, enabled it for NLB, configured cluster parameters the same for each one, and so on... ... And after doing this, network stops responding on both computers, because arp resolution fails on every VLAN adapter, until disabling NLB. ... A VLAN in a switch is a group of ports that are segmented with a new IP segment so that all members in the segment are on the same subnet. ...
    (microsoft.public.windows.server.clustering)
  • Re: VLAN as a DMZ
    ... Subject: VLAN as a DMZ ... VLAN to communicate with the switch (to change the VLAN memberships - Telnet ... It'd be just an isolated segment. ...
    (Security-Basics)
  • Re: VLAN interfaces on FreeBSD; performance issues
    ... >> The reason for wanting VLAN tagging is the machine has once NIC ... My goal is to make this machine a gateway for several servers that I ... need to segment that will be on different IP subnets. ... layer-2 separation for security. ...
    (freebsd-isp)
  • FW: problem in voip environment
    ... not configured to use the correct VLAN it may be defaulting to ... information about the DHCP option 176 see the Avaya LAN Administrators ... CSAG Lead Security Engineer ... vlan-static-bindig id y for telephony we are in mode access so ports are ...
    (Bugtraq)