Open cardosec

Case 7D034C · Network · L3 Applied

VLAN Hopping

Practise as: Explain it
  1. 01 What is it?
  2. 02 How is it abused?
  3. 03 How do you stop it?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. Switch spoofing: attacker negotiates a trunk via DTP on an auto/desirable port and gains access to all VLANs
  2. Double tagging: frame with outer native-VLAN tag and inner target tag; first switch strips outer, next forwards inner
  3. Double tagging is one-way only and requires attacker to be on the native VLAN of the trunk
  4. Fix: disable DTP (switchport nonegotiate), set access ports to access mode explicitly
  5. Use an unused native VLAN on trunks or tag native VLAN, and prune allowed VLANs on trunks

If the interviewer pushes back

  • Why can a double-tagged attack not easily receive return traffic?

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.