Re: VLAN interfaces on FreeBSD; performance issues
From: Chuck Swiger (cswiger_at_mac.com)
Date: 09/11/05
- Previous message: Chuck Swiger: "Re: VLAN interfaces on FreeBSD; performance issues"
- In reply to: Blake Covarrubias: "Re: VLAN interfaces on FreeBSD; performance issues"
- Next in thread: Aaron Glenn: "Re: VLAN interfaces on FreeBSD; performance issues"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
Date: Sun, 11 Sep 2005 10:16:57 -0400 To: Blake Covarrubias <blake@yfug.yumaed.org>
Blake Covarrubias wrote:
> On Sep 10, 2005, at 8:37 AM, Chuck Swiger wrote:
[ ... ]
>> fxp is a good NIC hardware. However, if you are trying to connect
>> two distinct subnets, playing ISO layer-2 games with VLANs is not
>> going to result in a good substitute for layer-3 IP routing.
>>
>> You cannot truthfully multihome a machine with a single NIC.
>
> My goal is to make this machine a gateway for several servers that I
> need to segment that will be on different IP subnets. I could always
> just alias the IP's to the NIC on the gateway machine, but I need
> layer-2 separation for security.
If you need layer-2 seperation for security, then you need to put each of these
machines or tiny subnets on seperate hubs or switches. Simply putting them all
onto one switch and putting ports onto different VLANs does not give adequate
isolation in practice even from non-malicious traffic, as you might discover if
you monitor for ARP traffic leaking through (especially under high packet rate
load).
A malicious user can use mechanisms discussed here:
http://www.sans.org/resources/idfaq/vlan.php
http://archives.neohapsis.com/archives/sf/pentest/2001-06/0139.html
"Try not to use VLANs as a mechanism for enforcing security policy. They are
great for segmenting networks, reducing broadcasts and collisions and so forth,
but not as a security tool."
> I'm doing this for co-located servers
> (hence the need for segmentation) I don't think its feasible to add a
> NIC for every new machine.
You don't need a seperate NIC or hub for each new machine, but you ought to
have one for each distinct security domain (or client, or whatever).
(If my packets and their packets all go to the same switch port, my traffic is
not actually being isolated from their traffic, VLAN tagging or no.)
-- -Chuck _______________________________________________ freebsd-isp@freebsd.org mailing list http://lists.freebsd.org/mailman/listinfo/freebsd-isp To unsubscribe, send any mail to "freebsd-isp-unsubscribe@freebsd.org"
- Previous message: Chuck Swiger: "Re: VLAN interfaces on FreeBSD; performance issues"
- In reply to: Blake Covarrubias: "Re: VLAN interfaces on FreeBSD; performance issues"
- Next in thread: Aaron Glenn: "Re: VLAN interfaces on FreeBSD; performance issues"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
Relevant Pages
- RE: Clueless firewall configuration ?
... attacker has access to your core switch. ... between the vlans (oh and
we are a big production site that relies on ... Does anyone care to comment on the security
issues a setup as this ... Download FREE whitepaper on how a managed service ...
(Pen-Test) - RE: Firewall and VLAN security design
... use a separate switch for your internal LAN. ... @Stake security review of VLANs
... IT Technical Security Officer ... "VLANs can enhance scalability, security,
and network management. ... (Security-Basics) - Re: Clueless firewall configuration ?
... One question I would ask is, "How does the switch respond if the ... between
the vlans (oh and we are a big production site that relies on ... Concerned about Web Application
Security? ... Download FREE whitepaper on how a managed service can ... (Pen-Test) - Re: Catalyst 3750G / Network design question
... that is - two static VLANs. ... stub routing and other L3 features not needed
where a basic L2 switch will ... getting back to the security .. ... While
I'm a 'network engineer' by profession and my job doesn't involve ... (comp.dcom.sys.cisco) - Re: Security Guidance - Part II
... Switches only switch traffic, they're not "intelligent". ... packets
from all VLANS. ... IDS on this span port. ... (comp.security.firewalls)