Vulnerability Development mailing list archives
Re: Vlans
From: Akatosh <akatosh () RAINS NET>
Date: Thu, 18 Jan 2001 09:52:03 -0500
Search for 'VLAN security' on securityfocus.com, there was a good discussion some year or so ago on the matter. Excellent reading. --------------- Edward Fahner Linux SA, PlanetComm.net, LLC aka. Akatosh .CU.Au, akatosh () rains net DC2.DwGmL--WT--SksCre+\Cvi+BflA(+r-v+++)N^MH+$-Fj~R+Ac+++!J+S+U-I--#V+++Q+Tc++ GCSd-s:-a---C++++UL++++P---L++++E-W++N+o?K-w---O-M--V-PS+PE?YPGPt+5++XR*!tvb++(+++)DI++D++Geh+r--y+ On Wed, 17 Jan 2001, Tim Salus wrote:
I am not certain if this is the place to ask this and if not please let me know where to send it. I have a client who has the following configuration Internet -> router -> firewall -> load balancer The connection from the router to the firewall is on a switch and the connection from the inside interface of the firewall is on the same switch. The separation is done using VLANS. I was taught this is bad due to 802.1q tagging and VLAN hopping using tagged packets. The problem is I can find very little information on this to prove my point. Also what if there is no 802.1q trunking being done. Is there still a problem with this? Is there an exploit to get around the firewall and do server flooding by jumping VLANS. No one can get on the firewall segment so what I need to know is can anyone on the internet cause a problem with this type of configuration. Thanks in advance Timothy L. Salus
Current thread:
- Re: Vlans, (continued)
- Re: Vlans Akatosh (Jan 18)
- Re: Vlans Lincoln Yeoh (Jan 22)
- Vlans Tim Salus (Jan 18)
- Re: Vlans Shawn Davenport (Jan 18)
- Re: Vlans TabascoJack (Jan 19)
- Re: Vlans Rainer Enders (Jan 22)
- Re: Vlans Shawn Badolian (Jan 23)
- Vlans Timothy L. Salus (Jan 23)
