
737373
© 2002, Cisco Systems, Inc. All rights reserved.
l2-security-bh.ppt
PVLAN Attack Mitigation
¥ Setup ACL on ingress router port:
IOS(config)#access-l 101 deny ip
localsubnet lsubmask localsubnet lsubmask
log
IOS(config)#access-l 101 permit ip any any
IOS(config-if)#ip access-group 101 in
¥ All known PVLAN exploits will now fail
¥ VLAN ACL (VACL) could also be used
Kommentare zu diesen Handbüchern