Official Lammle User Forum
|
#2
|
|||
|
|||
|
If you take the default Vl1 - which is the native and mgmt. Is not best practice to have them the same. Most designs have the management VL as another VL (although i admit i have seen many places that keep everything on VL1).
Best practice says shut down VL1, have the native as something else and the mgmt as something else. Further, each connection (trunk) between other switches should also use another native for further security. Cisco does recommend not have the native VL on trunks, in case an attacker hops from an access port to a trunk's native VL by sending frames that begin with DOT1Q headers. l though Cisco has proven this to be ineffective on Cisco switches. HTH.
__________________
Maddox Thomas-Clark 14/10/2008 Bean Thomas-Clark 18/09/2007 Big Evils Cisco World |
| Bookmarks |
| Tags |
| native vlan |
| Thread Tools | |
| Display Modes | |
|
|
All times are GMT -5. The time now is 07:43 AM.
















Threaded Mode