cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
729
Views
0
Helpful
1
Replies

VLAN Hopping on Native VLAN

oguarisco
Level 3
Level 3

Hi,

Is it possible to send tagged frames on a switched port which is configured as access with the VLAN ID equal to the native VLAN to do VLAN Hopping ???

What are the best practices to avoid VLAN Hopping ????

1 Reply 1

Hello,

I think what you describe is a doubel encapsulated VLAN hopping attack.

The document below talks about preventing this and other VLAN hopping attacks:

Layer 2 -- The Weakest Link

Security Considerations at the Data Link Layer

http://www.cisco.com/en/US/about/ac123/ac114/ac173/ac222/about_cisco_packet_feature09186a0080142deb.html

Hacking Layer 2: Fun with Ethernet Switches

http://www.blackhat.com/presentations/bh-usa-02/bh-us-02-convery-switches.pdf

Regards,

GP