Re: To vlan or not to vlan, that's the question
From: Xous - Jose R. Negreira (xous_at_xouslab.com)
Date: 03/31/05
- Next message: Stefan Monnier: "Re: X tunneling"
- Previous message: Xous - Jose R. Negreira: "Re: To vlan or not to vlan, that's the question"
- In reply to: pizzy: "Re: To vlan or not to vlan, that's the question"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
Date: Thu, 31 Mar 2005 12:28:58 -0300
pizzy, thank you too, man. :). About what u said:
"...for security reasons this may make sense but for performance reasons
you might want to use a vlan setup with Access Control List to secure
unwanted traffic."
So, if I understood u correctly: a router for uniting vlans is not
always needed? (Thought it IS needed).
Other question you said before, that you cannot get higher than Layer 4
on a switch. (Thought a switch could get higher to layer 2*), or in
other words, could implement filtering for MAC Address.
* considering this layers:
L5: Application
L4: TCP/UDP
L3: Network(IP)
L2: Link
L1: Physical
Regards,
-- Jose R. "Xous" Negreira [ *xous*at*xouslab_dot_com* ] XousLAB - http://www.xouslab.com iptableslinux - http://www.iptableslinux.com pizzy escribió: > Hmmm VLANs, why bother? I think it depends if you want to segment your > network logically. Depending on the features of the switch you buy, > will determine the security options you have to choose from, although > you're not going to get higher than Layer 4 on the switch for security. > But if your internal network is trusted then why would you firewall the > heck out it; these are business-to-business decisions, and are for > another discussion at another time. Let's carry on, a switch like > Extreme Networks will give you non-blocking, wire speed switching, but > if you want all your traffic to go slow path then pick a router. A > router in the middle will force all traffic to go slow path for routing > decisions between networks; for security reasons this may make sense > but for performance reasons you might want to use a vlan setup with > Access Control List to secure unwanted traffic. Whatever setup you > choose let the backbone have either a Cisco, Extreme, or Juniper Layer > 3 switch... > > Have fun! >
- Next message: Stefan Monnier: "Re: X tunneling"
- Previous message: Xous - Jose R. Negreira: "Re: To vlan or not to vlan, that's the question"
- In reply to: pizzy: "Re: To vlan or not to vlan, that's the question"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
Relevant Pages
|