<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi, in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/shutdown-ports-or-put-them-in-vlan/m-p/3096673#M907308</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Shutdown is the best and most secure option.&lt;/P&gt;
&lt;P&gt;If VLAN111 is enabled, users can abuse that VLAN to create there own uncontrolled private network.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Just my 2 cents.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;S.O.&lt;/P&gt;</description>
    <pubDate>Fri, 11 Aug 2017 21:54:47 GMT</pubDate>
    <dc:creator>software_onbekend</dc:creator>
    <dc:date>2017-08-11T21:54:47Z</dc:date>
    <item>
      <title>Shutdown ports or put them in VLAN?</title>
      <link>https://community.cisco.com/t5/network-security/shutdown-ports-or-put-them-in-vlan/m-p/3096671#M907297</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;
&lt;P&gt;I have always read how it is the best security practice to put unused ports on switch/router into shutdown state. However, at work they put them in unused VLAN which serves just for this purpose.&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-family: andale mono,monospace; font-size: 12pt;"&gt;The only config on that interface:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN style="font-family: terminal,monaco,monospace; font-size: 10pt;"&gt;#switchport mode access&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN style="font-family: terminal,monaco,monospace; font-size: 10pt;"&gt;#switchport access vlan 111&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;By the way, VLAN 111 is active.&lt;/P&gt;
&lt;P&gt;I searched a lot on this topic but still do not have the answer. Is it a good security practice? And is it better than shutting down the ports?&lt;/P&gt;
&lt;P&gt;Thank you very much for any help &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 14:12:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/shutdown-ports-or-put-them-in-vlan/m-p/3096671#M907297</guid>
      <dc:creator>glogloglik</dc:creator>
      <dc:date>2020-02-21T14:12:54Z</dc:date>
    </item>
    <item>
      <title>Personally I would shut them</title>
      <link>https://community.cisco.com/t5/network-security/shutdown-ports-or-put-them-in-vlan/m-p/3096672#M907304</link>
      <description>&lt;P&gt;Personally I would shut them down. It's no more effort to enable versus change their VLAN when they are in use. In fact, you could argue 'no shut' is easier to type than 'switchport access vlan xx' &amp;nbsp;&lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;I know in the case of auditors, they say ports should be disabled when not used. Some companies, and more highly restricted networks, specify that ports are not only shut down, but their network ports are completely unpatched from the switch as well.&lt;/P&gt;
&lt;P&gt;Back in the day of 'vlan hopping', shutdown was certainly the best method. I'd stick with it.&lt;/P&gt;</description>
      <pubDate>Sun, 06 Aug 2017 06:47:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/shutdown-ports-or-put-them-in-vlan/m-p/3096672#M907304</guid>
      <dc:creator>Bobby Stojceski</dc:creator>
      <dc:date>2017-08-06T06:47:26Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-security/shutdown-ports-or-put-them-in-vlan/m-p/3096673#M907308</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Shutdown is the best and most secure option.&lt;/P&gt;
&lt;P&gt;If VLAN111 is enabled, users can abuse that VLAN to create there own uncontrolled private network.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Just my 2 cents.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;S.O.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Aug 2017 21:54:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/shutdown-ports-or-put-them-in-vlan/m-p/3096673#M907308</guid>
      <dc:creator>software_onbekend</dc:creator>
      <dc:date>2017-08-11T21:54:47Z</dc:date>
    </item>
  </channel>
</rss>

