Re: about vlan ?

From: Cedric Blancher (blancher@cartel-securite.fr)
Date: 02/28/03


From: "Cedric Blancher" <blancher@cartel-securite.fr>
Date: Fri, 28 Feb 2003 16:02:06 +0100

Dans sa prose, brian nous ecrivait :
> but one physical interface can be configured to have multiple IP addresses ?

Yes, but then, all IP addresses are sharing the same ethernet broiadcast
domain (aka ethernet network), which is bad.
With VLANs, you have multiple logicial interfaces that are sharing the
same ethernet _devices_, but are not sharing the same ethernet broadcast
domain.

Once you've set an interface up with VLAN support, each logical interface
attached to it is equivalent to a physical interface attached to a VLAN on
the swith.

Talking about security, you have to care the fact that if your firewall is
linked with a dot1q link to a switch, then you _must_ consider that this
switch is part of the firewall, and _must_ be protected as such. If
someone manages to alter your switch configuration (especially VLAN
stuff), your firewall becomes useless.

-- 
 Je sais les forums sont plus longs à charger à cause de ces messages,
 mais comme à chaque message, vous en ajouter un voir plusieurs ça fait
 encore plus long, ce qui vous ramène as vos propres responsabilités.
 -+- OW in http://neuneu.mine.nu : T'avais qu'à pas répondre -+-


Relevant Pages

  • kgdb 2.0.5
    ... When using the ethernet interface, ... KGDB: Linux Kernel Source Level Debugger ... the questions about Ethernet network cards. ... +static int xlockholdcount = 0; ...
    (Linux-Kernel)
  • Re: kern/109815: wrong interface identifier at pfil_hooks for vlans + if_bridge
    ... address may be used by multiple physical interfaces. ... Ethernet frames in the stack. ... local interface at the L2. ... it can know which particular vlan the ...
    (freebsd-net)
  • Re: kgdb 2.0.5
    ... When using the ethernet interface, ... ++static int bufnum; ... ++static void kgdbeth_holdxlock ...
    (Linux-Kernel)
  • Re: Newbie trying to setup the Ethernet Connection...
    ... > Text says Ethernet Port. ... Above this in the list was resource LIN02 ... > step was to configure an interface, which I did by adding one under ... > option 1 of the TCP/IP menu and entered ...
    (comp.sys.ibm.as400.misc)
  • Wireless AND ethernet to same router
    ... Ever wonder what happens when you connect BOTH via wireless and wired ... ethernet to the same router? ... | Ethernet adapter Local Area Connection: ... Each interface gets a seperate IP address. ...
    (alt.internet.wireless)