[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Multiple IP's (virtual interfaces) on ONE VLAN?





--On May 22, 2008 10:04:02 AM -0700 Mike Bird <mgb-debian@yosemite.net> wrote:

Are you certain what they mean by VLAN's?  One would normally
configure the VLAN onto the switch ports and the computers would
use normal non-VLAN connections.  This is moderately more
secure than allowing each computer to decide which VLAN's it
wants to sniff.

Actually on any switch you're only going to hear the broadcast traffic unless you take other steps to trick the switch into sending packets for a different MAC address to your port. That also said any decent VLAN capable switch lets you decide what VLANs to allow on a particular port, even in trunk mode, most even allow you to control spanning tree operation as well. (hint: turn on at least bpduguard on your cisco devices facing untrusted/customer devices)


--
Michael Loftis
Modwest Operations Manager
Powerful, Affordable Web Hosting


Reply to: