<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Switches vlans in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/switches-vlans/m-p/3337128#M969320</link>
    <description>&lt;P&gt;Dears Mink,&lt;/P&gt;
&lt;P&gt;My vlan 1 interface is shut on all&amp;nbsp;switches but they were allowed on the trunk &amp;nbsp;still it will not have an effect of vlan hopping attack.&lt;/P&gt;
&lt;P&gt;thanks&lt;/P&gt;</description>
    <pubDate>Sat, 24 Feb 2018 12:45:26 GMT</pubDate>
    <dc:creator>adamgibs7</dc:creator>
    <dc:date>2018-02-24T12:45:26Z</dc:date>
    <item>
      <title>Switches vlans</title>
      <link>https://community.cisco.com/t5/network-security/switches-vlans/m-p/3337070#M969239</link>
      <description>&lt;P&gt;Dears,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;On every switch I have a vlan 1 interface in shut state but there are some ports assigned to vlan 1 as the default vlan , is it a high security risk to keep the ports in the default vlan though my vlan 1 interface is shutdown.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 15:25:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/switches-vlans/m-p/3337070#M969239</guid>
      <dc:creator>adamgibs7</dc:creator>
      <dc:date>2020-02-21T15:25:42Z</dc:date>
    </item>
    <item>
      <title>Re: Switches vlans</title>
      <link>https://community.cisco.com/t5/network-security/switches-vlans/m-p/3337116#M969240</link>
      <description>&lt;P&gt;if your rigorously shut the interface that have vlan 1 you should be good. and if your vlan1 interface 1 has no ip addresses you really cant route in and out of the vlan either.&lt;/P&gt;</description>
      <pubDate>Sat, 24 Feb 2018 11:57:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/switches-vlans/m-p/3337116#M969240</guid>
      <dc:creator>Dennis Mink</dc:creator>
      <dc:date>2018-02-24T11:57:10Z</dc:date>
    </item>
    <item>
      <title>Re: Switches vlans</title>
      <link>https://community.cisco.com/t5/network-security/switches-vlans/m-p/3337128#M969320</link>
      <description>&lt;P&gt;Dears Mink,&lt;/P&gt;
&lt;P&gt;My vlan 1 interface is shut on all&amp;nbsp;switches but they were allowed on the trunk &amp;nbsp;still it will not have an effect of vlan hopping attack.&lt;/P&gt;
&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Sat, 24 Feb 2018 12:45:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/switches-vlans/m-p/3337128#M969320</guid>
      <dc:creator>adamgibs7</dc:creator>
      <dc:date>2018-02-24T12:45:26Z</dc:date>
    </item>
    <item>
      <title>Re: Switches vlans</title>
      <link>https://community.cisco.com/t5/network-security/switches-vlans/m-p/3337130#M969321</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;You can and most likely will need to use a native VLAN on your trunk ports, at least on Cisco switches, other vendors do it differently. But what you have to remember that the security risk is more to do with VLAN 1 (default VLAN) being set as a native VLAN.&lt;/P&gt;
&lt;P&gt;You should change the native VLAN from being VLAN 1 to a new VLAN that you create. The native VLAN is used for a lot of management data such as DTP, VTP and CDP frames and also BPDU’s for spanning tree.&lt;/P&gt;
&lt;P&gt;When you get a brand new switch, VLAN 1 is the only VLAN that exists, this also means that all ports are members of this VLAN by default.&lt;/P&gt;
&lt;P&gt;If you are using VLAN 1 as your native VLAN, you have all the ports that you haven't configured to be part of this VLAN. So if an attacker connects to a port that is not used and not configured (because it's not used), he has straight away access to your management VLAN and can read and inject packets that could allow VLAN hopping or capture packets you don't want him/her to see, or worse, SSH into your switches/routers (never allow telnet).&lt;/P&gt;
&lt;P&gt;The advice is always to not use VLAN 1, so if an attacker or unwanted client connects and ends up on VLAN 1 and there is nothing configured on this VLAN, such as a useable gateway, they are pretty much stuck and can't go anywhere, while you native VLAN is something like VLAN 900 which is less likely to have any port access as it isn't the default VLAN.&lt;/P&gt;
&lt;P&gt;Alot of engineers do not disable unused ports and using VLAN 1 for important stuff leaves you in a situation where the access is open unless you use something like 802.1x. Engineers/Network admins forget and you have a little security hole that can benefit an attacker. If your VLAN 1 is not used and ports are left as default, it's not such a big deal because it is not used.&lt;/P&gt;
&lt;P&gt;Hope this helps you on your quest.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Deepak Kumar&lt;/P&gt;</description>
      <pubDate>Sat, 24 Feb 2018 12:51:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/switches-vlans/m-p/3337130#M969321</guid>
      <dc:creator>Deepak Kumar</dc:creator>
      <dc:date>2018-02-24T12:51:59Z</dc:date>
    </item>
    <item>
      <title>Re: Switches vlans</title>
      <link>https://community.cisco.com/t5/network-security/switches-vlans/m-p/3337141#M969322</link>
      <description>&lt;P&gt;well I am with deepak on this one. i.e. vlan 1 is the default native vlan. although you will most likely not need a native vlan, you are best off to assign native vlan another number like 999 and assigns no access ports to it.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 24 Feb 2018 13:11:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/switches-vlans/m-p/3337141#M969322</guid>
      <dc:creator>Dennis Mink</dc:creator>
      <dc:date>2018-02-24T13:11:07Z</dc:date>
    </item>
    <item>
      <title>Re: Switches vlans</title>
      <link>https://community.cisco.com/t5/network-security/switches-vlans/m-p/3337299#M969323</link>
      <description>&lt;P&gt;thanks Deepak and Mink,&lt;/P&gt;
&lt;P&gt;I have rated you both.&lt;/P&gt;</description>
      <pubDate>Sun, 25 Feb 2018 06:44:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/switches-vlans/m-p/3337299#M969323</guid>
      <dc:creator>adamgibs7</dc:creator>
      <dc:date>2018-02-25T06:44:01Z</dc:date>
    </item>
  </channel>
</rss>

