[c-nsp] vlans to customer - good practise / myth to bust !

Mikael Abrahamsson swmike at swm.pp.se
Tue Aug 4 15:56:16 EDT 2009


On Tue, 4 Aug 2009, vince anton wrote:

> what keeps on buzzing at the back of my mind is that I have a layer2
> connection (actually a number of them) from my switch to many switches (of
> customers) that i have no control over.

If each vlan only goes <custport> -> <routerport> and not <custport1> -> 
<custport2> then I'd say you have control.

> so do you typically use bpdufilter, only allow tagged vlans, not use vtp 
> - and this keeps things under control ?

Yes, I'd say so.

-- 
Mikael Abrahamsson    email: swmike at swm.pp.se


More information about the cisco-nsp mailing list