<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic security  question in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/security-question/m-p/1904576#M457010</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; To answer it in simple there is no security concern with the Internet router on the DMZ switch but you need take care of all the L2 Layer type of attack by hardening the Switch configuration.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 17 Apr 2012 12:29:28 GMT</pubDate>
    <dc:creator>Alexander Moorthy</dc:creator>
    <dc:date>2012-04-17T12:29:28Z</dc:date>
    <item>
      <title>security  question</title>
      <link>https://community.cisco.com/t5/network-security/security-question/m-p/1904571#M456995</link>
      <description>&lt;P&gt;Is it a security issue or concern to add the Internet router on the same DMZ switch but on a different VLAN. To  make the question clear  here is the setup.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The Internet router in on the outside interface of an ASA firewall and the DMZ switch is on the DMZ interface of the Firewall with a security level of 50.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support iPad App&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 22:54:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/security-question/m-p/1904571#M456995</guid>
      <dc:creator>helsayed78</dc:creator>
      <dc:date>2019-03-11T22:54:17Z</dc:date>
    </item>
    <item>
      <title>security  question</title>
      <link>https://community.cisco.com/t5/network-security/security-question/m-p/1904572#M456999</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Can anyone help out please?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;H&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Apr 2012 11:46:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/security-question/m-p/1904572#M456999</guid>
      <dc:creator>helsayed78</dc:creator>
      <dc:date>2012-04-17T11:46:08Z</dc:date>
    </item>
    <item>
      <title>security  question</title>
      <link>https://community.cisco.com/t5/network-security/security-question/m-p/1904573#M457002</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi H,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There are no security concerns if you plug the DMZ interface and the Internet Router on&amp;nbsp; the same switch until they are separated in differet vlans with correct cofiguration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Varun&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Apr 2012 11:55:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/security-question/m-p/1904573#M457002</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2012-04-17T11:55:30Z</dc:date>
    </item>
    <item>
      <title>security  question</title>
      <link>https://community.cisco.com/t5/network-security/security-question/m-p/1904574#M457004</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What about the L2 attacks ( VLAN hopping for example? )&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Apr 2012 12:02:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/security-question/m-p/1904574#M457004</guid>
      <dc:creator>helsayed78</dc:creator>
      <dc:date>2012-04-17T12:02:13Z</dc:date>
    </item>
    <item>
      <title>security  question</title>
      <link>https://community.cisco.com/t5/network-security/security-question/m-p/1904575#M457009</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi H,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For that your configurations needs to be strict, no traffic should be allowed over native vlans, instead they should be specified in access vlans. Do not set the trunks to auto negotiate. Such steps can be taken to mitigate such L2 attacks and gain access to your DMZ resources without passing through the ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Varun&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Apr 2012 12:23:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/security-question/m-p/1904575#M457009</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2012-04-17T12:23:03Z</dc:date>
    </item>
    <item>
      <title>security  question</title>
      <link>https://community.cisco.com/t5/network-security/security-question/m-p/1904576#M457010</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; To answer it in simple there is no security concern with the Internet router on the DMZ switch but you need take care of all the L2 Layer type of attack by hardening the Switch configuration.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Apr 2012 12:29:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/security-question/m-p/1904576#M457010</guid>
      <dc:creator>Alexander Moorthy</dc:creator>
      <dc:date>2012-04-17T12:29:28Z</dc:date>
    </item>
  </channel>
</rss>

