cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
366
Views
0
Helpful
1
Replies

Current Bug in VTP?

MaseBarnes
Level 1
Level 1

Hi,

in my opinion it is only possible to send crafted VTP packets over the default VLAN and over trunk ports, correctly? So, clients connected to normal VLAN access ports don't have a chance to attack my VTP domain?

Any experts?

Thanks,

MB

1 Accepted Solution

Accepted Solutions

leonvd79
Level 4
Level 4

Mase,

VTP messages are relayed over trunk ports only using reserved multicast address 0100.0CCC.CCCC. So an attack from a host is highly unlikely, but I would not rule it out.

To protect your switched network, you can either protect VTP with authentication or disable VTP by using transparent mode.

HTH

--Leon

* Please rate ALL posts.

View solution in original post

1 Reply 1

leonvd79
Level 4
Level 4

Mase,

VTP messages are relayed over trunk ports only using reserved multicast address 0100.0CCC.CCCC. So an attack from a host is highly unlikely, but I would not rule it out.

To protect your switched network, you can either protect VTP with authentication or disable VTP by using transparent mode.

HTH

--Leon

* Please rate ALL posts.