CCNP Exam Prep Tips and Must Knows about Mitigating VLAN Attacks

laptopstudy155319814Things You Need to Know about Mitigating VLAN Attacks

VLAN Hopping
Unused Ports:

  • Shut down all unused ports
    • Configure all unused ports to access mode
      • Configure an access VLAN on all unused ports to an unused VLAN
        • Configure a native trunk VLAN on all unused ports to be an unused VLAN
        • Trunk Ports

          • Configure a trunk port with trunk mode on and disable trunk negotiation
            • Configure a native trunk VLAN on trunk ports to an unused VLAN
              • Configure the allowed VLANs on the trunk ports, and do not allow the native VLAN
              • VLAN Access Control Lists

                • Switch(config)# access-list 100 permit ip 10.1.1.0 0.0.0.255 any
                  • Switch(config)# MAC access-list extended BACKUP_SERVER
                    • Switch(config-ext-mac)# permit any host 0000.1111.2222
                      • Switch(config)# VLAN access-map TEST 10
Please support our Sponsors here :