VLAN design/safety sanity check

It depends on your managed switch brand what do with factory default settings and passing vlan. In some case we saw that vlan were dropped, but in 80% of cases, it will only forward vlan as they arrive, ignoring them. Of course you can try and capture on a span port if you see traffic tagged or not passing with all ports untagged vlan1.

Pay attention on vlan hopping and double tag exploit, so you should have native vlan different from a production one on the trunk port router side and host/VMware side. I know that you handle router and host/VMware, so nobody should be able to do it, but at the first iso27001 assessment they will told you that DMZ should have its own physical dedicated cables or at least prevent vlan double tag and if using Cisco vlan hopping using no negotiate switch port

/r/networking Thread