cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements

1715
Views
2
Helpful
2
Replies
glogloglik
Beginner

Shutdown ports or put them in VLAN?

Hello all,

I have always read how it is the best security practice to put unused ports on switch/router into shutdown state. However, at work they put them in unused VLAN which serves just for this purpose.

The only config on that interface:

#switchport mode access

#switchport access vlan 111

By the way, VLAN 111 is active.

I searched a lot on this topic but still do not have the answer. Is it a good security practice? And is it better than shutting down the ports?

Thank you very much for any help :)

1 ACCEPTED SOLUTION

Accepted Solutions
Bobby Stojceski
Beginner

Personally I would shut them down. It's no more effort to enable versus change their VLAN when they are in use. In fact, you could argue 'no shut' is easier to type than 'switchport access vlan xx'  :-)

I know in the case of auditors, they say ports should be disabled when not used. Some companies, and more highly restricted networks, specify that ports are not only shut down, but their network ports are completely unpatched from the switch as well.

Back in the day of 'vlan hopping', shutdown was certainly the best method. I'd stick with it.

View solution in original post

2 REPLIES 2
Bobby Stojceski
Beginner

Personally I would shut them down. It's no more effort to enable versus change their VLAN when they are in use. In fact, you could argue 'no shut' is easier to type than 'switchport access vlan xx'  :-)

I know in the case of auditors, they say ports should be disabled when not used. Some companies, and more highly restricted networks, specify that ports are not only shut down, but their network ports are completely unpatched from the switch as well.

Back in the day of 'vlan hopping', shutdown was certainly the best method. I'd stick with it.

View solution in original post

Hi,

Shutdown is the best and most secure option.

If VLAN111 is enabled, users can abuse that VLAN to create there own uncontrolled private network.

 

Just my 2 cents.

S.O.

Create
Recognize Your Peers
Polls
Which of these topics should we host an event in the Community?

Top Choice: pxGrid (35%)

Content for Community-Ad