Re: Catalyst 3750G / Network design question



"BernieM" <c@xxxxxxxxx> wrote in message
news:GGlEg.12595$rP1.6313@xxxxxxxxxxxxxxxxxxxxxxxxxxxxx
<Bod43@xxxxxxxxxxxxx> wrote in message
news:1155642888.919727.141140@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxx

Merv wrote:

ensure they implement your design with two separate switches

The proposed installation is not best practise.


Not that I usually object to anyone spending
money on network equipment, however the 3750
seems overkill for the application described -
that is - two static VLANs.

Consider a 2960G (all GBE) for the inside
and a 2950 (if they still do them) for the outside,
unless of course you have a GBE internet connection.

I would guess that you will still have change.
lly
If you need Routing at wire rate then of course
the 3750 is an excellent choice. Maybe its PoE
that you need.


That's a good point bod43. Even with a base IOS in a 3750 you still have
stub routing and other L3 features not needed where a basic L2 switch will
do the job. Gbit is definitely questionably. Even a 2960 10/100 sounds
sufficient. getting back to the security .. it's disturbing that people
that should know better are actually recommending that sort of topology.

While I'm a 'network engineer' by profession and my job doesn't involve
direct responsibility for 'security' I've been around enough (15+ years)
to
know that nobody that wants to be taken seriously recommends vlan
separation
as a layer of security. It's use it strictly limited to separation of
broadcast domains. Sure you apply at least acl type restrictions when you
need to have 'some form' of restrictions internally but never rely on
vlans
for 'security'.

if you use the Cat 6k firewall switch module, then all segregation is done
via VLAN.....

A lot of this came out of some tests where an engineer can build a packet to
jump from 1 VLAN to another.

But
1. you need kit that doesnt stop this happening - at least the higher end
Cisco switches (ie 3560 / 3750 / Cat 6k) are proof against this attack.
2. the attacker needs layer 2 access to the network since they need to
manipulate MAC headers and vlan tags - which isnt normally directly
accessible across the Internet.

The assumption here is that you dont have routing enabled between segregated
vlans.

A much more sensible reason to avoid security barriers using vlans is "ease
of misconfiguration" - multiple secure VLANs on a switch with internal
routing support is a recipe for future problems from finger trouble....

FWIW we use both options at work - some "heavy" security is done by
physically separating networks and a firewall link between them.

But when you need lots of security zones and they are at comparable security
levels, then using VLAN segregation is appropriate and much easier than
managing dozens of different stackables (esp as Cisco dont make small
switches with dual power supplies) - YMMV of course.

BernieM


BernieM

--
Regards

stephen_hope@xxxxxxxxxxxx - replace xyz with ntl


.



Relevant Pages

  • RE: Clueless firewall configuration ?
    ... attacker has access to your core switch. ... between the vlans (oh and we are a big production site that relies on ... Does anyone care to comment on the security issues a setup as this ... Download FREE whitepaper on how a managed service ...
    (Pen-Test)
  • RE: Re: [fw-wiz] Vlans as effective security measures?
    ... >>investing in this kind of technology is to manage bandwidth ... >>traffic, not provide security. ... Practically speaking, VLANs are usually used to control traffic, and are ... > users computer or the users login to the network. ...
    (Firewall-Wizards)
  • Re: VLAN Help
    ... clear how your network is setted up. ... the remote office LAN and add a port which will connect to this LAN ... Once you do that you have to add a tagged port to the 2 VLANS (yours ... > Our network center runs the same switch but the Layer 3 Version. ...
    (Security-Basics)
  • RE: Rogue IP Address
    ... capability that you paid for when buying the switch, ... someone will holler about his network not working. ... prospectus based upon the core principle concepts of security. ... This ALL INCLUSIVE curriculum utilizes lectures, case studies and true hands-on utilization ...
    (Security-Basics)
  • RE: Firewall and VLAN security design
    ... use a separate switch for your internal LAN. ... @Stake security review of VLANs ... IT Technical Security Officer ... "VLANs can enhance scalability, security, and network management. ...
    (Security-Basics)