04-14-2003 09:11 PM - edited 03-02-2019 06:40 AM
Hello. We have connected two 1900 switches (one 24 port and the other 12 port). On the 24 port switch we have configured 2 vlans and vtp as a server - second switch setup as a vtp client. After enabling this configuration, vlans from the first switch were downloaded to the second. We started to test. (Remeber that in thist configutation there is no router, only trunk port) To test isolation, we connected two hosts to the server switch and then to the client switch: first both hosts to difrent vlans - no ping connection, and then to the same vlans- ping ok!!. Everything was good, after this we have made next simply test - one of us have unpluged one of the hosts form the same vlan, and then very fast connected it to the diferent vlan on the second switch. We have noticed that if this operation is done very fast, both host on difrent vlans can communicate without router !!!!!!!!!! Why?- is this a bug, any solution of this problem?
04-14-2003 10:21 PM
what is your trunk encapsulation and the vlan number assigned to your client swtich port which was connected to your test PC. And waht is your vlan number you created on your server switch?
04-14-2003 11:46 PM
Trunk encapsulation IEEE 802.1q (Trunk ports A on both switch set in ON mode) SAID 10010 for vlan10 and 10020 for vlan20. Assigned vlan ports for vlan10 : server switch 1-12 and for client switch ports 1-6, for vlan20 ports on server switch 13-24 and on client switch ports 7-12. I also want add, that everything works fine if the time between reconnection is grater than few seconds. But if I will reconnect very fast one host to different vlan (for example both host 1 and 2 are in vlan10, and now I will fast reconnect host 2 to vlan20, then the host 2 and host 1 (different vlan) can communicate without the router),he can communicate with host from previous vlan10 without the router.
04-15-2003 12:23 AM
Hi,
I've heard about this already, it's called VLAN hopping, see http://www.sans.org/resources/idfaq/vlan.php
But I was never able to reproduce this fault in my lab - I'm not using Cat1900.
I tried it with 3524 and I was not able to hop between VLANs - so I thought it was fixed in cureent IOS already.
There is a good document on CCO:
http://www.cisco.com/warp/customer/784/packet/jan03/pdfs/p30-cover.pdf
with excellent links at the "Best Practices for Layer 2 Networks" part.
Regards,
Milan
04-15-2003 01:20 AM
Thank you for your help. This event was very strange for me, now I know a little more about this hopping.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide