VLAN Security
Troy McMillan · 2018
This chapter describes the security implications of a Private VLAN (PVLAN) and of a native VLAN. When hosts are segregated into VLANs, they are also placed into separate IP subnets. Service providers often find this arrangement to be problematic, especially when there is need for additional security across a VLAN being shared by multiple customers. A feature that can be a solution in these cases is the implementation of private VLANs. These provide separation within a VLAN at layer 2, while still leaving all members of the original VLAN (called the primary VLAN) in the same subnet. When the router receives the packet, the router rewrites the destination MAC address to that of the target and sends the packet to the target. It is the presence of the MAC address of the router in the packet, rather than that of the target, that causes this to be possible. This causes the packet to be coming from the router, which is allowed since the router is on a promiscuous port. Port access lists (PACLs) are applied to layer 2 interfaces either on a layer 2 switch or on a multilayer switch. When applied to a layer 2 interface on a multilayer switch, they can be applied only inbound.