Re: VALN hopping

From: Kenton Smith (listsks_at_yahoo.ca)
Date: 09/29/05

  • Next message: Lance.Druger_at_wellsfargo.com: "RE: Software Firewalls"
    Date: Thu, 29 Sep 2005 12:01:46 -0400 (EDT)
    To: security-basics@securityfocus.com
    
    

    It's my view that VLAN's were never intended to be
    used as a security measure, rather they're for traffic
    isolation. A byproduct of this is that it is more
    difficult to access the traffic on the "other"
    network. Unless you're going to have a firewall or
    IDS/IPS between the two networks it's pretty trivial
    for someone with much knowlegde to get from one VLAN
    to another. As another level of a defense in depth
    strategy a VLAN is great but it shouldn't really be
    considered a way to secure traffic or hosts.

    Kenton

    --- josh@tstc.edu wrote:

    > WWe are having a heated discussion about using
    > VLAN's as a type of DMZ, so
    > I am asking the experts. I prsonally like to see
    > physical isolation;
    > however, our network person doesn't feel there is a
    > threat of VLAN
    > hopping. Please let me know your opinions.
    >
    > Thank you,
    >

            

            
                    
    __________________________________________________________
    Find your next car at http://autos.yahoo.ca


  • Next message: Lance.Druger_at_wellsfargo.com: "RE: Software Firewalls"

    Relevant Pages

    • Re: Clueless firewall configuration ?
      ... "drop" an IDS on a VLAN without adding network taps or other tricks. ... Having untrusted traffic on your core switch can cause the ... VLAN hopping attacks. ... Download FREE whitepaper on how a managed service can ...
      (Pen-Test)
    • Re: ERS 8600, simple setup, IP, VLANs, etc.
      ... management port is just used to hang an IP address to. ... associated with an interface, such as a VLAN. ... fairly functionally homogenous network), but something that is ... or OS virtuallization - except that networks have been doing this kind of ...
      (comp.dcom.sys.nortel)
    • Re: intrepid qemu broken?
      ... -snapshot write to temporary files instead of disk image files ... Network options: ... connect the user mode network stack to VLAN 'n' and send ... -serial dev redirect the serial port to char device 'dev' ...
      (Ubuntu)
    • intrepid qemu broken?
      ... -snapshot write to temporary files instead of disk image files ... Network options: ... connect the user mode network stack to VLAN 'n' and send ... -serial dev redirect the serial port to char device 'dev' ...
      (Ubuntu)
    • Re: MS Windows through QEMU
      ... create a new Network Interface Card and connect it to ... VLAN 'n' ... -serial dev redirect the serial port to char device 'dev' ...
      (Fedora)

  • Quantcast