Security Best Practices for VLANs and Trunking
•Always use a dedicated VLAN ID for all trunk ports
总是启用一个专用的vlan 来放置所有的trunk端口
•Disable unused ports and put them in an unused VLAN
禁用不使用的端口,并且放到一个不使用的Vlan中
•Be paranoid: Do not use VLAN 1 for anything
本征Vlan 如 Vlan 1中不要存在任何端口
•Disable auto-trunking on user facing ports (DTP off)
不要使用DTP协议
•Explicitly configure trunking on infrastructure ports
明确配置Trunk及其端口
•Use all tagged mode for the Native VLAN on trunks
在本征Vlan上打上Tag