RE: Different terms for the same or more secure?



no true. you can only have one subnet per vlan, however, private vlan can be
used to further isolate the
vlans. also if your using a switch with l3 capability, intervlan routing can
be used (SVI).

192.168.1.0/24 = VLAN 10
192.168.2.0/24 = VLAN 11

you can't have 192.168.1.0 and 192.168.2.0 on VLAN 10. VLAN is a L2 not L3,
therefore seperating the
broadcast domain independantly.

-----Original Message-----
From: eliterhythm@xxxxxxxxx [mailto:eliterhythm@xxxxxxxxx]
Sent: Thursday, August 24, 2006 8:50 AM
To: security-basics@xxxxxxxxxxxxxxxxx
Subject: Re: Different terms for the same or more secure?

Hey hylton,
The main advantage of having a VLAN is that they provide physical
independence while defining a logical entity. Say one of your account person
sits on first floor & in accounts vlan can be in the same subnet with the
other account person who sits at 10th floor.
However VLAN as a term, generally is considered to define a
single subnet but you can also define two or more subnets in a single VLAN.

In simplest words u can c a vlan as advanced stage of a subnet with many
advanced options and facilities.
As per the security is concern, i cant see one more secure than
another. both are eqally secure (or unsecure) however a vlan is much more
flexible than a subnet.

---------------------------------------------------------------------------
This list is sponsored by: Norwich University

EARN A MASTER OF SCIENCE IN INFORMATION ASSURANCE - ONLINE The NSA has
designated Norwich University a center of Academic Excellence in Information
Security. Our program offers unparalleled Infosec management education and
the case study affords you unmatched consulting experience.
Using interactive e-Learning technology, you can earn this esteemed degree,
without disrupting your career or home life.

http://www.msia.norwich.edu/secfocus
---------------------------------------------------------------------------








----------------------------------------------------------------------------
----------------------------------------------------------------------------
----------------------------------------------------
This e-mail and any attachments thereto are intended only for use by the
addressee(s) named herein and may contain proprietary and/or confidential
information. If you are not the intended recipient of this e-mail, you are
hereby notified that any dissemination, distribution or copying of this
e-mail, and any attachments thereto, is strictly prohibited. If you have
received this e-mail in error, please immediately notify
Postmaster@xxxxxxxxxx and permanently delete the original, any attachments,
any copies thereof, and any printouts thereof.

---------------------------------------------------------------------------
This list is sponsored by: Norwich University

EARN A MASTER OF SCIENCE IN INFORMATION ASSURANCE - ONLINE
The NSA has designated Norwich University a center of Academic Excellence
in Information Security. Our program offers unparalleled Infosec management
education and the case study affords you unmatched consulting experience.
Using interactive e-Learning technology, you can earn this esteemed degree,
without disrupting your career or home life.

http://www.msia.norwich.edu/secfocus
---------------------------------------------------------------------------



Relevant Pages

  • Re: How to set my MAC address
    ... because the VLAN isolation fails between the wifi side and the wired ... ports that I started experimenting with the 2nd subnet feature. ... there is no option to isolate the wireless from the VLAN. ... give out the password of my own wifi network, ...
    (uk.comp.sys.mac)
  • Re: VLANS and subnetting
    ... every VLAN has to be a seperate subnet. ... still talk to the ISP core switch as it were a / 24 network. ...
    (comp.dcom.lans.ethernet)
  • Re: VLANS and subnetting
    ... every VLAN has to be a seperate subnet. ... still talk to the ISP core switch as it were a / 24 network. ...
    (comp.dcom.lans.ethernet)
  • Re: Single domain two IP subnets
    ... Each individual VLAN is effectively on a separate NIC; ... Chances are it is an attempt for us to do your homework. ... I have a single Domain DC and DNS is on same server ... Subnet B - 192.168.1.65-126 ...
    (microsoft.public.win2000.dns)
  • Re: Different terms for the same or more secure?
    ... Could someone define each for me and the list and also why one is more secure than the other. ... One definition of "subnet" is that it is a contiguous block of host addresses. ... a LAN, ... So what does a VLAN do that a subnet doesn't and why is one better than the other? ...
    (Security-Basics)