09-15-2006 12:38 AM - edited 03-03-2019 05:03 AM
Hi,
in my opinion it is only possible to send crafted VTP packets over the default VLAN and over trunk ports, correctly? So, clients connected to normal VLAN access ports don't have a chance to attack my VTP domain?
Any experts?
Thanks,
MB
Solved! Go to Solution.
09-15-2006 12:45 AM
Mase,
VTP messages are relayed over trunk ports only using reserved multicast address 0100.0CCC.CCCC. So an attack from a host is highly unlikely, but I would not rule it out.
To protect your switched network, you can either protect VTP with authentication or disable VTP by using transparent mode.
HTH
--Leon
* Please rate ALL posts.
09-15-2006 12:45 AM
Mase,
VTP messages are relayed over trunk ports only using reserved multicast address 0100.0CCC.CCCC. So an attack from a host is highly unlikely, but I would not rule it out.
To protect your switched network, you can either protect VTP with authentication or disable VTP by using transparent mode.
HTH
--Leon
* Please rate ALL posts.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide