Re: Do you think switchport block unicast is very hard to

From: Serhat Aslan (serhatworks@gmail.com)
Date: Wed Jul 25 2007 - 08:24:31 ART


 Hi John,
 Trunk mechanism is a carrier protocol for vlan informations, block-unicast
mechanism is kind of broadcast preventation (Roughly/not technical sense ).
 For the unknown IP. The switch ca send to another switch. It can say that
ip-mac is not mine " it could be yours, so I am sending" , or at the
result of accessive cam table overflow behavior arp-flooding
attack/asymetric routing problem/insufficient memory. We can assume that
"flooding unicast" is switch last resort job, for unknown ips.
  So we can independently think the relation between trunk mechanism and
block-unicast.

Serhat Aslan

On 7/25/07, johngibson1541@yahoo.com <johngibson1541@yahoo.com> wrote:
>
> I know ARP would bypass the blocking. Otherwise the blocking
> would make the port useless.
>
> But which direction of ARP can "plumb" the blockage?
>
> You think the ARP request from the being protected
> port would do the trick right?
>
> But what happens if we block the trunk links ?
> Is it still analyzable ?
>
> _______________________________________________________________________
> Subscription information may be found at:
> http://www.groupstudy.com/list/CCIELab.html



This archive was generated by hypermail 2.1.4 : Sat Aug 18 2007 - 08:17:42 ART