L29
VLANs, VLAN hopping and MAC flooding
Cram this first — memory hook
Virtual Local Area Network = separate rooms; hopping = crossing rooms; Media Access Control flooding = stuffing the switch's directory.
Exam trap
creation is switch configuration; a alone is not a complete firewall policy. spoofing and flooding are different attacks.
The slide facts
flooding targets switch address learning; hopping abuses segmentation and tag/native- behavior. Switch security includes disabling unused ports and limiting device access.
If you have time — extra
A Virtual Local Area Network () creates a logical Layer 2 broadcast domain on a switch. Access ports normally belong to one data ; trunks carry multiple VLANs using tags. Inter- communication requires routing and appropriate access rules. A switch learns source Media Access Control () addresses to decide where to forward frames. flooding fills its learning table with excessive identities; some unknown-unicast traffic may then be flooded to other ports within the relevant . Behavior varies by hardware and configuration, so it does not make every switch globally act like a hub. hopping tries to cross a boundary. Double tagging can exploit a native-/tag-processing arrangement under specific conditions. Switch-spoofing/trunk-negotiation abuse is an added related mechanism. Restrict trunk formation, configure native/allowed VLANs deliberately, secure user ports and limit learned identities appropriately.
Walkthrough
Draw the intended membership and trunks, identify where routing/policy should occur, then examine unexpected tags, learning or trunk state. Match the control to the mechanism rather than applying one generic fix.