Re: Hardware recommendation for firewalls (more than 4 NICs)

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
From: Gordon Grieder
Date: Saturday, July 12, 2008 - 6:24 am

On Sat, Jul 12, 2008 at 12:24:46AM -0400, Jason Dixon wrote:


Yep.

A few years ago when the "vlan insecurity bullshit" was all the rage we
happened to be upgrading our LAN to gigabit. I was a bit leery from the
experiences of dealing with Nortel's retarded (and proprietary)
protocol-based VLAN crap. But I didn't want that to taint our future.

So before deciding on a course of action (VLAN or physical separation) we
picked up a couple of Cisco 2960G's, put them on my workbench and *BEAT THE
FUCKING SHIT OUT OF THEM* trying all these VLAN hopping exploits that were
talked about. Nothing seemed to work: the switches did their job. On our
older Nortel 450's we did see some VLAN traffic leaking out when the things
were flooded but those units dated back to the late 90's or so. Tech changes
and improves.

Fast forward and we've got these 2960G's everywhere, a couple of 3750G's
doing the L3 work and feeding to the hardware out to the world. Nearly 20
VLANs going through various trunks (single gig and etherchannel). The stuff
just works well when configured properly.


 Gord
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
Re: Hardware recommendation for firewalls (more than 4 NICs), Giancarlo Razzolini, (Fri Jul 11, 9:09 pm)
Re: Hardware recommendation for firewalls (more than 4 NICs), Gordon Grieder, (Sat Jul 12, 6:24 am)
Re: Hardware recommendation for firewalls (more than 4 NICs), Jacob Yocom-Piatt, (Sat Jul 12, 8:08 am)
Re: Hardware recommendation for firewalls (more than 4 NICs), Siegbert Marschall, (Mon Aug 11, 8:06 am)