Skip to main content

Redux: VLANs in the DMZ

A topic that I blocked about, VLANs in the DMZ was taken up both by Ivan Pepelnjak and Colin McNamara. Colin points out that security is more about what is done in the complete path and not at a single point.
There are a few extra points I would mention:
  • Data should not be stored in a DMZ terminating incoming external connections. These should be limited to processing.
  • It is a theoretical physical exploit and not a remote one.
  • There has been no major security incident attributed to VLAN hopping as a cause.
 After all these years, with cloud and virtualization up to our eyeballs, I wonder if Ivan will admit I was right?

Comments

Popular posts from this blog

LDWin: Link Discovery for Windows

LDWin supports the following methods of link discovery: CDP - Cisco Discovery Protocol LLDP - Link Layer Discovery Protocol Download LDWin from here.

easywall - Web interface for easy use of the IPTables firewall on Linux systems written in Python3.

Firewalls are becoming increasingly important in today’s world. Hackers and automated scripts are constantly trying to invade your system and use it for Bitcoin mining, botnets or other things. To prevent these attacks, you can use a firewall on your system. IPTables is the strongest firewall in Linux because it can filter packets in the kernel before they reach the application. Using IPTables is not very easy for Linux beginners. We have created easywall - the simple IPTables web interface . The focus of the software is on easy installation and use. Access this neat software over on github: easywall

STG (SNMP Traffic Grapher)

This freeware utility allows monitoring of supporting SNMPv1 and SNMPv2c devices including Cisco. Intended as fast aid for network administrators who need prompt access to current information about state of network equipment. Access STG here (original site) or alternatively here .