Z+

L29

VLANs, VLAN hopping and MAC flooding

Cram this first — memory hook

Virtual Local Area Network = separate rooms; hopping = crossing rooms; Media Access Control flooding = stuffing the switch's directory.

Exam trap

creation is switch configuration; a alone is not a complete firewall policy. spoofing and flooding are different attacks.

The slide facts

flooding targets switch address learning; hopping abuses segmentation and tag/native- behavior. Switch security includes disabling unused ports and limiting device access.

Close the book — check

Does unknown-unicast flooding automatically cross every Virtual Local Area Network on a switch?

Scenario

A user-facing switch port unexpectedly negotiates a trunk. What control is relevant?

Retrieve it

Authored for this desk. Not claimed to be CompTIA exam questions. Options shuffle; the correct choice stays correct.

Does unknown-unicast flooding automatically cross every Virtual Local Area Network on a switch?

If you have time — extra

A Virtual Local Area Network () creates a logical Layer 2 broadcast domain on a switch. Access ports normally belong to one data ; trunks carry multiple VLANs using tags. Inter- communication requires routing and appropriate access rules. A switch learns source Media Access Control () addresses to decide where to forward frames. flooding fills its learning table with excessive identities; some unknown-unicast traffic may then be flooded to other ports within the relevant . Behavior varies by hardware and configuration, so it does not make every switch globally act like a hub. hopping tries to cross a boundary. Double tagging can exploit a native-/tag-processing arrangement under specific conditions. Switch-spoofing/trunk-negotiation abuse is an added related mechanism. Restrict trunk formation, configure native/allowed VLANs deliberately, secure user ports and limit learned identities appropriately.

Walkthrough

Draw the intended membership and trunks, identify where routing/policy should occur, then examine unexpected tags, learning or trunk state. Match the control to the mechanism rather than applying one generic fix.

Supporting video

Watch after the notes. Watching does not mark the topic practiced.

VLAN Hopping— Switch spoofing and double tagging for L29.

MAC Flooding— MAC flooding versus hopping — different attacks.

VLANs and Trunking— VLANs and 802.1Q trunks — the legitimate switching before hopping/flooding attacks.

Z+ · the last-lap desk · N10-009

Search

Lessons, ports, glossary