5 ms·
VLAN is the obvious and most cost-effective mitigation
by 88 5y ago
VLAN is the obvious and most cost-effective mitigation
- allarm 5y agoNot really. VLAN provides segmentation, but it does not provide any mechanisms to limit access to other vlans in your network - which are most likely routed by your router. You will need to add some L3 filtering (acls/iptables/whatever) to isolate segments.
- formerly_proven 5y agoThat's only true if use of VLAN tags is controlled by hosts; if you use a smart switch to assign VLANs to ports it's pretty much as-if you have multiple, physically separated networks.
- addingnumbers 5y agoSegmenting your broadcast domains doesn't help much if traffic is routed freely between them.
- spookthesunset 5y agoAll nice, but now you need managed switches and stuff plus some amount of unbillable time to configure it all and fix it when it breaks. Might be worth it if your bill rate accommodates it though.
- neverartful 5y agoSounds like a great approach. Any recommendations for such a switch for WFH?
- ArchOversight 5y agoYou'd still need the router to tag/untag those VLAN's and allow traffic to flow. So if the router does VLAN tagging but just routes between the different network segments you haven't fixed anything. You'd also need a firewall, and to configure it correctly.