2016年7月11日 星期一

Network Design, part 1

Since email or other communications may not be safe enough for discussion of network topology design, some sensitive info are suggested to be processed as following.

  • VLAN ID numbers should be replaced with dummies, since 802.1q ID may be useful for forging fake packets.
  • ACL for routers / switch , such as allow/deny between VLAN, is regarded as part of security policy, which is prohibited to be revealed.
  • Routing table is also prohibited to be revealed, since L3 info such as IP restriction policies  will be included.

沒有留言:

張貼留言