|
|
Question : Problem: Is it secure using cisco vlans within a DMZ
|
|
I am considering using a no routed vlan within a DMZ, ie instead of having a dedicated switch for that DMZ, simply create a vlan (without creating any layer 3 interfaces) and assign any ports accross my switch fabric to that vlan. I am running 6509's with VTP, and STP uplinks to edge 3548's. Is there any/many security issues with this?
|
Answer : Problem: Is it secure using cisco vlans within a DMZ
|
|
It is fairly safe, but under special circumstances/flaws in the IOS, traffic can bleed over. 802.1x EAP traffic is an example.
|
|
|
|