07-13-2005 05:01 AM
Why is there such a setting called managment VLAN? I can manage my switches from any VLAN even though it is set to VLAN2
07-13-2005 06:03 AM
Where specificly did you see this reference? There used to be switches that needed their management interface on VLAN 1...
Rgds, Chris.
07-13-2005 08:12 AM
I did not read it but I have done it. You can chooses any VLAN(olny one) to be a management VLAN. But you can access any switch from any VLAN as long as it has an IP even if it is not set to the managment VLAN.
07-13-2005 10:01 AM
Ok, now I know where you're coming from.
Yes, you are right you can do that.
However, it is considered good practice to segregate traffic.
For instance, if you have your switch at the same subnet as the users connected to your switch and one has a virus that creates a broadcast storm, you will likely lose access to your switch and cannot shutdown this user...
Or you might have a security policy in place that will not allow snmp traffic from your user segment to get to your switch...
Just two reasons of the top of my head, why you would prefer to have a separate VLAN for managing your switches.
HTH, Chris.
07-13-2005 11:48 AM
Ahhhhh I did't think about that. Thank You
07-13-2005 12:34 PM
Besides the excellent examples provided by Chris, I'd invite you to read the SAFE BluePrint titled Security Blueprint for Enterprise
HTH
Steve
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide