What is one method that can be used to prevent VLAN hopping?

What is one method that can be used to prevent VLAN hopping?

What is one method that can be used to prevent VLAN hopping?

A.
Configure ACLs.

B.
Enforce username and password combinations.

C.
Configure all frames with two 802.1Q headers.

D.
Explicitly turn off DTP on all unused ports.

E.
Configure VACLs.

Explanation:
When securing VLAN trunks, also consider the potential for an exploit called VLAN hopping.
Here, an attacker positioned on one access VLAN can craft and send frames with spoofed
802.1Q tags so that the packet payloads ultimately appear on a totally different VLAN, all
without the use of a router.
For this exploit to work, the following conditions must exist in the network configuration:
+ The attacker is connected to an access switch port.
+ The same switch must have an 802.1Q trunk.
+ The trunk must have the attacker’s access VLAN as its native VLAN.
To prevent from VLAN hopping turn off Dynamic Trunking Protocol on all unused ports.
Reference
http://www.cisco.com/web/CA/events/pdfs/L2-security-Bootcamp-final.pdf



Leave a Reply 0

Your email address will not be published. Required fields are marked *