Compare cert salaries and plan your next career move
alliasneo wrote: » Hey Guys, Just going pretty heavily in to VLAN configuration and I keep hearing that VLAN's can help with network security because it segments the PC's off from the rest of the network. At the moment though I find this hard to believe because at first if you just configure the switch with VLANS, then fine yes the PC's can't communicate. But as soon as you get to say a 'router in a stick' scenario you're enabling intervlan routing and everything pings just fine - so where is the security in this?
pham0329 wrote: » ^what he said. When all your hosts are on one vlan, there's really no easy way to prevent one device from communicating with the other. When you have them in separate vlans, you can implement ACL, or not even route between them.
alliasneo wrote: » This is interesting. So if I were to implement switchport protected on a 24 port catalyst, no other device could ping another device through that switch without the means of a Layer 3 router for intervlan routing? I was thinking, well if two pc's can't communicate what's the point? but then I thought well for e-mail and things it would go off to a server and then back in to your network and the same for networked hard drives. so you wouldn't ever need to ping/directly communicate with another PC right?
alliasneo wrote: » This is interesting. So if I were to implement switchport protected on a 24 port catalyst, no other device could ping another device through that switch without the means of a Layer 3 router for intervlan routing?
Compare salaries for top cybersecurity certifications. Free download for TechExams community.