01-11-2009 02:29 AM - edited 03-06-2019 03:22 AM
I am using VLAN2 for management and VLAN3 and above for data. Do I still need to assign an IP address to VLAN1?
Many thanks for you help
Mark
01-11-2009 04:02 AM
Mark
If there are no devices that are in vlan 1 then no you do not need to assign an IP address for vlan 1 interface and you should shutdown vlan 1 interface.
Jon
01-11-2009 05:01 AM
Hello Mark,
for security reasons the best thing is to:
- shut SVI vlan1 if exists
- never use vlan 1 even for unused ports.
A suggestion is to use a dedicated parking Vlan for unused ports that:
has no Layer 3 services on it
it is never used as Native Vlan on an 802.1Q trunk in your campus.
the reason for not using Vlan1 for unused ports is that in any case a switch tells more to a PC if the port is in Vlan1.
if you don't use Vlan1 neither for management neither for data you are on the right path from a security point of view.
Hope to help
Giuseppe
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide