Velocity Reviews - Computer Hardware Reviews

Velocity Reviews > Newsgroups > Computing > Cisco > Vlans on a switch for Public and Private networks

Reply
Thread Tools

Vlans on a switch for Public and Private networks

 
 
daniel
Guest
Posts: n/a
 
      03-08-2005
Hi,

At a small company we want to use a switch (2950) to do our private
network, but also vlan off 4 ports to do handle the internet
connection / public network.

So of the 4 "Public network" vlan ports, one is the internet
connection from the ISP and 3 others are their firewall and 2 public
servers.

So the firewall has one cable from the "public network" VLAN and one
cable from the "internal network" VLAN. But the whole thing is cabled
from one switch.

Is that a good idea? Are we more open to security issues than if we
have the usual router before the switch?

Hope that makes sense.

Many Thanks,

Daniel.
 
Reply With Quote
 
 
 
 
Brian V
Guest
Posts: n/a
 
      03-08-2005

"daniel" <> wrote in message
news: om...
> Hi,
>
> At a small company we want to use a switch (2950) to do our private
> network, but also vlan off 4 ports to do handle the internet
> connection / public network.
>
> So of the 4 "Public network" vlan ports, one is the internet
> connection from the ISP and 3 others are their firewall and 2 public
> servers.
>
> So the firewall has one cable from the "public network" VLAN and one
> cable from the "internal network" VLAN. But the whole thing is cabled
> from one switch.
>
> Is that a good idea? Are we more open to security issues than if we
> have the usual router before the switch?
>
> Hope that makes sense.
>
> Many Thanks,
>


Hi Daniel,

Yes, you are opening yourself to all kinds of security problems. VLAN hoping
for 1. Best practices would move all but 2 of those ports away from the
outside. Router ethernet and Firewall outside. Servers should never be
"public" (unless it's a bastion device) and should be protected by the
firewall and put on a DMZ. The outside ports should be on their own switch,
not on a shared switch.

-Brian


 
Reply With Quote
 
 
 
 
Walter Roberson
Guest
Posts: n/a
 
      03-08-2005
In article <zdOdnZUEaNNUMLDfRVn->,
Brian V <> wrote:
:Yes, you are opening yourself to all kinds of security problems. VLAN hoping
:for 1.

Cisco fixed all the vlan hopping problems years ago. Your switch
has to be misconfigured for such an attack to work (but watch
otu for double encapsulation.)

http://www.cisco.com/application/pdf...008012ed31.pdf


--
'The short version of what Walter said is "You have asked a question
which has no useful answer, please reconsider the nature of the
problem you wish to solve".' -- Tony Mantler
 
Reply With Quote
 
 
 
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
microsoft.public.certification, microsoft.public.cert.exam.mcsa, microsoft.public.cert.exam.mcad, microsoft.public.cert.exam.mcse, microsoft.public.cert.exam.mcsd loyola MCSE 4 11-15-2006 02:40 AM
microsoft.public.certification, microsoft.public.cert.exam.mcsa, microsoft.public.cert.exam.mcad, microsoft.public.cert.exam.mcse, microsoft.public.cert.exam.mcsd loyola Microsoft Certification 3 11-14-2006 05:18 PM
microsoft.public.certification, microsoft.public.cert.exam.mcsa, microsoft.public.cert.exam.mcad, microsoft.public.cert.exam.mcse, microsoft.public.cert.exam.mcsd loyola MCSD 3 11-14-2006 05:18 PM
microsoft.public.certification, microsoft.public.cert.exam.mcsa, microsoft.public.cert.exam.mcad, microsoft.public.cert.exam.mcse, microsoft.public.cert.exam.mcsd realexxams@yahoo.com Microsoft Certification 0 05-10-2006 02:35 PM
microsoft.public.dotnet.faqs,microsoft.public.dotnet.framework,microsoft.public.dotnet.framework.windowsforms,microsoft.public.dotnet.general,microsoft.public.dotnet.languages.vb Charles A. Lackman ASP .Net 1 12-08-2004 07:08 PM



Advertisments
 



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57