VLAN on Cisco Catalyst
- From: Keme <KEMEsixtwonullsix@xxxxxxxx>
- Date: Sun, 10 Sep 2006 23:19:04 +0200
I am getting conflicting advice from various sources concerning VLAN security. I have several Catalyst 2950 switches in my network, running one VLAN with public access (including wireless unrestricted access), and domain-controlled workstations on another. I classify those as low and medium security zones, respectively. I will now set up a network commanding higher security in the same physical space, and due to construction issues and safety precautions in the buildings, installing extra cables will be very expensive. I'm thinking of creating a new VLAN instead.
I get some warnings about the possibility of fixing a packet header to make traffic cross over between VLANs. Is that possible if all switchports have the communication explicitly set? (i.e.: ports connected to other Catalysts are set to Trunk mode, and ports towards the client side are set to access mode.) With no ports in auto mode, I'd think that such "trunk spoofing" would fail.
If such attacks are still possible, how serious could they be?
- Can the attacker get a response, or is it only one way?
- If two way communication is available, would it then be possible to do ARP poisoning, and could MiM attacks succeed?
Are there viable options for hardening the setup?
- Should I set up SSL/VPN channels to secure the network?
- The "high security" VLAN is not needed everywhere. Should I keep the VLAN undefined on the other switches, or is it better to define it and not assigning it to any port?
The high security nodes are mostly self sufficient (only occasional need for network) so DoS is probably not an issue. Eavesdropping and intrusion could be critical, though.
Any comments on the subject are welcome!
.
- Follow-Ups:
- Re: VLAN on Cisco Catalyst
- From: Volker Birk
- Re: VLAN on Cisco Catalyst
- From: Walter Roberson
- Re: VLAN on Cisco Catalyst
- Prev by Date: Vasco Digipass Implementation Details
- Next by Date: Re: VLAN on Cisco Catalyst
- Previous by thread: Vasco Digipass Implementation Details
- Next by thread: Re: VLAN on Cisco Catalyst
- Index(es):
Relevant Pages
|
|