[nsp] leaking vlans on a cat2950/cat6500-msfc2

Turpin Mark Contr AFCA/GCF Mark.Turpin at scott.af.mil
Fri Sep 19 10:29:22 EDT 2003


> -----Original Message-----
> From: Matt Stockdale [mailto:mstockda at logicworks.net]
> Sent: Thursday, September 18, 2003 12:49 PM
> To: cisco-nsp at puck.nether.net
> Subject: [nsp] leaking vlans on a cat2950/cat6500-msfc2
> 
> 
> 
> suggestions?
> 

Good ole leaky VLANs.

http://www.sans.org/resources/idfaq/vlan.php
http://www.cisco.com/en/US/products/hw/switches/ps708/products_white_paper09186a008013159f.shtml

"it was concluded that the traffic from VLAN 1 
was allowed to hop to other VLANs because the
trunk port was also set (implicitly) to native VLAN 1."

Why did the 2950(s) send it?  I'm guessing it wasn't unicast?

cheers,
Mark



More information about the cisco-nsp mailing list