当我在一个端口上错误地标记stream量(像潜在的攻击者那样进行VLAN跳转)时,我应该能够看到端口上的入口stream量到这个VLAN – 就像在pipe理交换机上禁用VLAN入口过滤?
更长的解释:我已经被告知Netgear和Allied Telesis设备,默认情况下vlan入口过滤未启用,并且VLAN成员仅适用于出口stream量。 因此,我认为在VLAN 100上的非成员端口上的入口VLAN 100标记的分组将被接受入口,但是由于vlan成员的出口过滤行为,发送方不会接收到响应(如icmp echo reply)。
我一直在做一些实验工作,并希望确定这个function是如何工作的。 也许有人可以开导我?
我不认为你的假设有什么根本性的错误,每个VLAN有一个单一的列表,包括启用的端口,stream量是标记还是不标记。 出口过滤是VLAN分离function的基础,不允许端口传输他们不负责的stream量。
Netgear将入口过滤定义为:
Ingress Filtering - When enabled, the frame is discarded if this port is not a member of the VLAN with which this frame is associated. In a tagged frame, the VLAN is identified by the VLAN ID in the tag. In an untagged frame, the VLAN is the Port VLAN ID specified for the port that received this frame. When disabled, all frames are forwarded in accordance with the 802.1Q VLAN bridge specification.
所以看起来你的假设是正确的,它会接受stream量并将其转发给该组中的其他成员,但返回stream量将由出口filter过滤掉。