Have a Great Independence Day!

Search:

Writers' Community!

SearchWarp Home Submit An Article Frequently Asked Questions Contact Author Login
Article Submission
We Need YOUR Articles!
We'll Promote Them for FREE!

Author Login

New Authors
Register Here


Now Serving 6,991 Authors
48,193 Quality Articles
& 3,179 Current Users Online!
Featured Authors
Marty RicKard (1,954)
Dianne Lehmann (2,017)
Robert Melaccio, Sr. (3,932)
Avis Ward (9,013)
Laura Trahan (29,559)
Dan Bimrose (280)
James Taylor (1,175)
David Tanguay (6,027)
Mike Fak (2,994)
Danny Davids (12,531)
Terry Mitchell (655)
Mr. Keith (1,882)
Susan Thom (8,136)
Missing Link (828)

View All Featured Authors
Most Recent
CCNA, CCNP, CCENT, And Cisco Security Practice Exam Questions: Static Routes, Honeypots, And More!

CCNA Security, CCNP, And Cisco CCNA Practice Exam Questions: DHCP, OSPF, Router Lockdowns, And More!

CCNA, CCNP, and CCENT Cisco Practice Exam: Radius, OSPF, And More!

CCNA, CCNP, and Cisco CCENT Practice Exam Questions: Switches, Frames, IPv6, And More!

Cisco CCNA, CCNP, And CCENT Practice Exam Questions: DHCP, BGP Route Reflectors, And More!

CCNA, CCNP, And CCENT Cisco Practice Exam Questions: Binary Conversions, OSPF ASBRs, And More!

Cisco CCNA, CCENT, and CCNP Practice Exam Questions: Frames, OSPF, Authentication Proxy, And More!

The New CCNA Security, Voice, and Wireless Certifications Mean Opportunity For You!

Cisco CCNA, CCENT, and CCNP Practice Exam Questions: Binary Conversions, RIP, STP, and More!

Cisco CCNA and CCENT Practice Exam: 10 Questions on Point-To-Point Connections, PPP, and HDLC

Home » Categories » Computers & Networking » Technical Certification » Cisco CCNP Certification / BCMSN Exam: Defending Against VLAN Hopping Attacks » Printer Friendly

Cisco CCNP Certification / BCMSN Exam: Defending Against VLAN Hopping Attacks

Rated 4 out of 5
Rate It  /  View Comments  /  View All Articles submitted by Chris Bryant CCIE 12933
Submitted Tuesday, May 22, 2007
Submitted by: Chris Bryant CCIE 12933 (14,375) Gold Level Author Hall of Fame Top 100 Verified Account Contact Chris Bryant CCIE 12933
The Bryant Advantage
Log in to become a member of Chris Bryant CCIE 12933's Fan Club!


During our Cisco CCNP BCMSN certification exam preparation, we've seen how intruders can use seemingly innocent ARP and DHCP processes can be used to harm our network, so it shouldn't come as any surprise that Dot1q tagging can be used against us as well!

One form of VLAN Hopping is double tagging, so named because the intruder will transmit frames that are "double tagged" with two separate VLAN IDs. As you'll see in our example, certain circumstances must exist for a double tagging attack to be successful:

The intruder's host device must be attached to an access port.

The VLAN used by that access port must be the native VLAN.

The term "native VLAN" tips us off to the third requirement - dot1q must be the trunking protocol in use, since ISL doesn't use the native VLAN.

When the rogue host transmits a frame, that frame will have two tags. One will indicate native VLAN membership, and the second will be the number of the VLAN under attack. In this example, we'll assume that to be VLAN 100, with the native VLAN set as VLAN 25.

The trunk receiving this double-tagged frame will see the tag for VLAN 25, and since that's the native VLAN, that tag will be removed and then transmitted across the trunk - but the tag for VLAN 100 is still there!

When the switch on the other side of the trunk gets that frame, it sees the tag for VLAN 100 and forwards the frame to ports in that VLAN. The rogue now has successfully fooled the switches and has hopped from one VLAN to another.

This is why you often see the native VLAN of a network set to a VLAN that no host on the network is a member of - that stops this version of VLAN Hopping right in its tracks.

Notice that I said "this version". We’ll take a look at another VLAN Hopping tactic in the next installation of my CIsco CCNP BCMSN certification exam tutorial series!

Chris Bryant, CCIE #12933, is the owner of The Bryant Advantage, home of free CCNP exam and CCNA Certification tutorials, The Ultimate CCNA Study Package, and Ultimate CCNP Study Packages.

You can also visit his blog, which is updated several times daily with new Cisco certification articles, free tutorials, and daily CCNA / CCNP exam questions! Details are on the website.

For a FREE copy of his latest e-books, “How To Pass The CCNA" and “How To Pass The CCNP", just visit the website! You can also get FREE CCNA and CCNP exam questions every day!

Take the exclusive CCNA Mastermind Boot Camp with The Bryant Advantage!






Reprint Rights

Log in to become a member of Chris Bryant CCIE 12933's Fan Club!

Comments on this article:
No comments yet.


Was this article helpful to you? Leave a Public Comment or Question:

 

This Article has been viewed 85 times.
Article added to SearchWarp.com on Tuesday, May 22, 2007
View other articles written by Chris Bryant CCIE 12933 (14,375) Gold Level Author Hall of Fame Top 100 Verified Account Contact Chris Bryant CCIE 12933


If you found this article interesting, you may want to check out:

Disclaimer:  All information on this site is provided for informational purposes only! By no means is any information presented herein intended to substitute for the advice provided to you by any health care or other professional or organization.


Today's Most Popular
Cisco CCNA Exam Tutorial: What's A Collision Domain?

Cisco CCNA Certification Exam Tutorial: Route Summarization

Cisco Certification: The Definitive Guide To ARP, RARP, IARP, and Proxy ARP

Cisco CCNA / CCNP Home Lab Tutorial: Access Server Configuration

Cisco CCNA Certification: Everything You Need To Know About Telnet!

CCNA / CCNP / BCMSN Exam Tutorial: VLAN Trunking Basics

Cisco CCNP / BSCI Exam Tutorial: EIGRP Route Summarization

Cisco CCENT / CCNA Certification Exam Tutorial: Logging Synchronous And Exec-Timeout Commands

Cisco CCNA 640-802, CCENT, And CCNP Practice Exam Questions: HDLC, PPP, OSPF Routes, And More!

Cisco CCNA / CCNP Certification: Creating A Roadmap For Success

Home  |  FAQ's  |  Contact  |  Terms of Service  |  Article Submission Guidelines  |  Reprint Rights  |  Article Categories  |  Writers' Contests  |  Privacy  |  Mission / About
Copyright © 1999-2008 SearchWarp.com, All Rights Reserved - SearchWarp.com is an IcoLogic, Inc. Company