2.1e PVLAN/VACL Flashcards

20%

1
Q

Passos configuracao PVLAN

A
  1. criar a vlan principal
  2. criar as vlans privadas (indicando se sao community ou isoladas)
  3. criar vinculo da vlan principal com as vlans privadas (associacao)
  4. especificar cada tipo de interface (promiscua/ host) e qual vlan privada ela esta associada
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Configuracao PVLAN

A
  1. Configurar PVLAN
    vlan
    private-vlan [primary/community/isolated]

2Criar Vinculo (na vlan primaria)
vlan (Y)
private-vlan primary
private-vlan association (X)

  1. Determinar o tipo de interface e as vlans associadas
    switchport mode private-vlan [host/promiscuous]
    HOST
    switchport private-vlan host-association (Y X)
    PROMISCUOUS
    switchport private-vlan mapping (Y X)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

comandos de verificacao PVLAN

A
sh vlan private-vlan 
sh vlan private-vlan type
sh int (x) switchport
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

observacoes sobre PVLANS

A
  1. usar modo VTP transparent ou VTPv3
    As versoes 1 e 2 do vtp nao enviam informacoes sobre as vlans privadas
  2. Informacoes das PVLANs sao transmitidas por trunks 802.1q, portanto eh possivel ter multiplos switches com as msmas pvlans (garantir que o tronco permita todas as vlans e q as vlans estejam presentes em todos os switches no caminho)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Protected ports (configuracao)

A

Garantir que dispositivos nao acessem algumas portas especificas

portas protegidas nao comunicam com outras portas protegidas

Configuracao
interface X
switchport protected

Verificar
sh int X switchport

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Vlan ACL

o que eh e como aplicar

A

Afetam como os pacotes sao transmitidos dentro de uma Vlan
TCAM realiza os matchs e as acoes

Configurados como vlan access-maps
Sao avaliadas em sequencia, de acordo com o numero

  1. Criar uma ACL padrao p identificar o trafego
  2. Criar a VACL p especificar match e acoes
  3. Criar Vlan filter list para definir em qual VLAN vai ser aplicada a regra
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Configuracao VLAN ACL

A

cria uma acl normal p identificar trafego
ip access-list (y)
permit ip host x.x.x.x host y.y.y.y

vlan access-map (nome) [num_sequencia]
match ip address [acl-num/nome]
match mac address [nome-acl]
action < drop / forward {capture} / redirect >

vlan filter (nome) vlan-list (X)

show vlan access-map

How well did you know this?
1
Not at all
2
3
4
5
Perfectly