Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: VLAN in CheckPoint FW1 Secure Platform |
|---|---|
| Date: | Tue, 04 Oct 2005 11:26:30 -0600 |
Multiple IP's don't give separation of traffic except by layer 3 route, which is easily defeated. VLAN's aren't foolproof either, but getting around one of those will typically require exploiting a bug or hole in some level of the network itself rather than changing an IP address or next-hop route (assuming your network is well built and secure to begin with, which is outside the scope of this thread).
- Ralph
Hi Sin,
Thanks for reply. But it sounds like a multihome IPs to me. Having a single network card with multiple IPs.
What good does VLAN do in here?
Cheers,
Bill
--- sin <sin@pvs.ro> wrote:
Bill Smith wrote:
Hi folks,
I do understand about VLAN in the switches
environment, but a bit
confused about VLAN in SPLAT.
Can anyone explain, what exactly VLAN is used for
in SPLAT and give me
an example.
VLAN in SPLAT is done by the underlying OS (mainly using vconfig and 8021q kernel module).
an example of using VLANs in SPLAT would be to have let's say different DMZ zones wihout having to have a physical interface in the firewall for each zone.
be aware that if you want to use VLANs in SPLAT for NG-AI R55 you have to assing an IP address to the physical interface you wish to attach VLAN subinterfaces to (if you don't do that, sysconfig won't let you create VLAN interfaces).
sin
__________________________________ Yahoo! Mail - PC Magazine Editors' Choice 2005 http://mail.yahoo.com
-- Skinny Motorsports, Inc. -- www.skinnymotorsports.com -- - Colorado's retail and trackside dealer for Komodo gear - Your source for laptimers and data acquisition equipment - Aftermarket and OEM parts and performance accessories
Main: 720-249-4791 / Fax: 720-249-2455 Email at: rforsythe@5280tech.com
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | Re: VLAN in CheckPoint FW1 Secure Platform, Mike Ulsh |
|---|---|
| Next by Date: | VPN FW1 CHECKPOINT VS ROUTER DLINK, Ricardo Duque Olaya |
| Previous by Thread: | Re: VLAN in CheckPoint FW1 Secure Platform, sin |
| Next by Thread: | Re: VLAN in CheckPoint FW1 Secure Platform, Ralph Forsythe |
| Indexes: | [Date] [Thread] [Top] [All Lists] |