Port Access mode allow tagged frames ?

Hello,
From my understanding Cisco Catalyst switch port access mode only allow untagged frames to be received and proceeded. Tagged frames received on access mode port should be discarded.
But I have found in BCMSN course Student Guide following phrase
If a non-802.1Q-enabled device or an access port receives an 802.1Q frame, the tag data is
ignored, and the packet is switched at Layer 2 as a standard Ethernet frame.
Is in this case term access related to non Cisco equipment ? Or where are some Cisco Catalysts HW/SW combinations in which access mode port accept also tagged frames ?
With Best Regards
Tomas

Hello Tomas,
802.1Q tagged frames with a vlan-id = access vlan of the port are accepted on Cisco Catalysts.
for Sure it was in 2004-2005 when I did L2 security tests and read about the following:
This is the basis for one of the L2 security attack that is called vlan hopping:
if you send a frame with two 802.1Q tags and:
a) the external tag vlan-id = port access vlan
b) the same vlan is used as native vlan in a inter-switch trunk
the attacker can send a frame from vlan X to vlan y bypassing L3 security and routing devices.
the recommendation is to use as native vlan a dedicated vlan for all trunks that is never used on access ports.
Hope to help
Giuseppe

Similar Messages

  • Does anyone know how I might be able to access picture frame in IOS 6 while in Guided Access mode..?

    Does anyone know how I might be able to access Picture Frame while being in Guided Access mode..?

    I don't exactly understand your issue but if your stuck in guided access press and hold the power and home until you see your device turns off keep holding then when you see the apple startup logo let go (this is called a hard reset or a respring) this will force you out of guided access and into the home screen where you can unlock the device with out being stuck in guided access
    If this does not help you please ignore this comment

  • Serries 200 VLAN to 100 Serries Switches Can't Talk (Access Mode, Untagged)

    Physical Setup:
    2 Internet Connection (Internal and Hosting)
    1 Series 200 Switch
    4 Series 100 Switchs
    6 VMware ESXi hosting boxes
    200 Series port layout
    P1 - Internet (Hosting)
    P12 - Internet (Internal)
    P3-4, 14-15 - 100 series switches
    P5-7, 16-18 - ESXi Hosts
    My plan is to have
    P1 be on VLAN 10
    P2 on VLAN 5
    P3-4,14-15 on VLAN 5
    P5-7,16-18 as Trunks for VLAN 5 and 10
    The idea being that I will use VMware's tagging on the servers to allow it to have VMs for both networks while still keeping them logically separated at the switch level.  I know how to do this in VMware, just having problems getting the series 200 switch configured correctly for the VLANs.
    From default configurations for the switch I Added VLAN 5
    Then I Configured P3-4, 14-15 as Access Ports, Untagged for VLAN 5 with PVID 5
    My understanding is hat this will allow any VLAN 5 tagged packet to go out of these ports (Stripping the VLAN 5 tag as it goes), and it will tag all incoming untagged packets on these ports for VLAN 5; Thus allowing the series 100 switchs and all attached machines to participate in VLAN 5 without any of those devices knowing anything about VLANs.
    At this point I tired going from one of these ports with untagged traffic to a machine on another port.  I was unable to communicate.  Am I missing something\misunderstanding how to set this up?
    Oh and the default VLAN (VLAN 1) does still exist at this point, but P3-4, 14-15 where automatically excluded from it when I stuck them in Access Mode, witch I believe I want, since only VLAN 5 should be able to use these ports.
    Any help\pointers are greatly appreciated.

    A member of which VLAN ID is that device from which you trying to reach that switch?
    Is that device directly connected to switch WasteWaterSG30010MPP? If yes, to which port?
    If you are connecting from different VLAN than VLAN2, are you using routing between VLANs? Where is that routing device connected to?
    > I also have another switch that connects to the network through this switch and am able to telnet to it.
    that second switch member of same VLAN 2? Or management is part of different VLAN?
    ..too few information to be able to give you final answer.

  • Using TImed Access mode on Airport Extreme with other routers in bridge mode. Not working as expected.

    I am trying to setup timed access mode on my airport extreme in order to limit the times devices can connect to my network, but I am having some trouble.
    My setup is as follows  Cable Modem ---> Airport Extreme ---> Netgear router
    The Airport is running DHCP and the Netgear is in bridge mode. The only purpose of the Netgear is to provide a wireless access point for older b/g wifi devices. The Netgear is connected to the Airport by an ethernet cable from one of its LAN ports. All ip addresses are supplied by the Airport.
    When I list a device mac number in the Airport extreme's timed access table it does seem to block the device if the device trys to connect to the airport's wireless service, but the device is still able to obtain service through the Netgear wireless service. I want the device to be blocked on both wireless networks. I thought this would work since all DHCP is on the airport. Why is the Airport allowing the device to connect when it comes in through the Netgear?
    In this example the device I am trying to block is 5c:59:48:ba:28:d2.
    Looking at the log on the airport I see the following entry when the device (when permitted) connects to the airport wireless
    Nov 30 22:43:12
    Severity:5
    Associated with station 5c:59:48:ba:28:d2
    If instead the device connects to the Netgear wireless I see the following log entry on the airport (this connection gets through even if the mac address above is listed as blocked on the airport)
    Dec 01 10:46:29
    Severity:5
    Connection accepted from [fe80::223:12ff:fe29:acfe%bridge0]:54774.
    It appears that the Netgear router (while bridging the network) is somehow modifying the mac address format in a way that the airport does not recognise it as the device to block.
    What can I do to fix this?
    Thanks.

    The Netgear wireless server has control over what what devices are allowed to connect.
    Unless you tell the Netgear what devices you want to allow to connect, it will allow any wireless device to connect as long as it knows the wireless network password.
    IF.... .you were using two AirPort Extremes, and not a Netgear, the two Extremes would communicate to each other....so you would only have to enter Timed Access settings on one router and other AirPort would automatically pick those settings up.
    But, even this was not the case until the last year or so when Apple updated firmware.  A few years ago, you might have had 2 Apple AirPort Extremes on the network, but you still had to manually set up Timed Access on both devices separately.
    Bottom line, you need to setup the equivalent of Timed Access on the Netgear router.

  • My external hard drive goes in to constant access mode and really slows down my computer

    I'm using an external hard drive for time machine.  After working for an hour or so the drive goes into a constant access mode and realy slows down my IMac.  I look at activity monitor and everything looks good, no high CPU usage or memory issues.  The only fix is to use the power button to shut down my IMac.  After restart it works fine for a while.
    If I turn off time machine the problem seems to not happen.  I tried disk utility on the external hard drive and it says the dirve is fine.  I change out external drives and the problem still occures.  Any thoughts?

    I didn't realize my profile stated otherwise.
    Please check near the bottom of your original post above to see OS X (10.7.2).  You might want to update that to avoid confusion and save some time in the future.
    OK, please take a deep breath.
    Apple does not officially support Time Machine backups to a drive at the USB port of the AirPort Extreme....likely because it is not reliable. You might want to review this Apple Support document to confirm:
    http://support.apple.com/kb/HT2038
    So, we are not going to be able to provide you with much assistance on that issue.
    Some users seem to be able to make this work....some have some problems....and some (like me) who have tried this have nothing but problems.
    Sorry, I can't help on this one, but maybe another user who has had better luck will post to provide his secrets.
    The iTunes and iPhoto libraries and files are my only copies now.  I moved everything from my Macbook to the external then deleted the originals.
    Not sure if you have thought about this.
    If you deleted the "originals", then your only copy of your data is on one hard drive. You have no backups if the drive has a problem.
    A minimum backup plan would be to have a copy of important data on two different drives. When....not if...one drive fails, you have the data on the "other" drive.
    You have no "other" drive according to the information that you have provided.
    Further.....Time Machine backs up the changes on your Mac. At some point....you cannot know when.....Time Machine will pick up the change on your Mac and delete the iTunes and iPhoto data from your Time Machine backups.
    The files might stay there a few months, or even longer. But, I have seen instances where the files were deleted within a week or two.
    So my advice would be to only delete data from your Mac that you can afford to lose.

  • Accessibility mode

    Hi, my son has enabled accessibility mode accidentally
    The only thing the phone will now allow is swiping, how can i turn this mode off?
    (I cant tap the screen to enter the settings menu to do it manually)
    Thanks

    After much hair pulling I discovered that you must triple tap when in accessibility mode
    Still wasnt able to scroll when in settings menu but was able to use the search function to get to accessibility and then disable from there
    Problem solved

  • Low Level Serial Port Access

    This question has gone unanswered several times on this forum in the past but I thought I would try it once more.
    Is there any Java API that is in, or will work with J2ME to allow direct read and write to the serial port similar to the functionality that javax.comm provides for j2se.
    This would be useful for a project where a palmos device is used to communicate with equipment used to monitor industrial processes.

    Some MIDP 1.0 devices support access to the Serial
    Port.
    I have done it with Motorola i85, i50 (iDen) and
    Motorola T720i.
    I think 95cl also supports it. I'm ALSO having problems with serial port access on
    my T-Mobile Moto T720i phone. I've had MUCH success
    with the Nextel i85, i50, i95cl, etc phones, but the
    same code isn't running on the T720i.
    What do I need to do differently???
    Thanks,
    -Tim

  • 3750X 10G uplink interfaces in access mode

    Hi all,
    just asking, any one knows if its possible to configure an 10G interface from a network module in a 3750 X switch in ACCESS MODE?

    Hi Hans,
    As mention you can use Tengig port to connect to Server same configuration as normal access port on Gig interface but check SFP transceiver at switch whether it is compatible with server end  SFP.
    Also if your server is is connected to Tengig port there over Subscription issue on uplink if it is 1 gig link.
    Br.
    Mohseen Patel 

  • I am stuck on the Subway Surfers app in guided access mode the info its giving me to fix it is a liar! none of the buttons will work all I can do is lock it unlock it and play subway surfers. I cannot turn it off and refuse to let it die. HELP ME PLEASE!!

    Ok I dont understand this SOS!!!! Please dont tell me to restart my Ipad Cause none of the buttons work except the lock button and that will not allow me to turn it off please help all suggestions are welcome.

    What you need to do is triple-press the HOME BUTTON three times. You will be prompted to enter your passcode. This will bring up the options for guided-access mode and you will then need to click "End" in the top corner.
    Guided-access mode must have accidentally been enabled by triple-clicking the home button.

  • Auto wifi reconnect in guided access mode

    Hi - I am using an iPad in Guided Access mode for a kiosk. I am using a browser as the main application and everything seems to be working great accept when I lose Wifi signal I can't get the browser to refresh the screen when it reconnects to the wifi. I have tried putting code into my page that say to refresh every "X" minutes and it doesn't work.
    Any ideas on a setting I might be missing in the settings area that will allow for an application to refresh after losing wifi that will bring the webpage back up?
    Thanks so much!!!

    Inputting an incorrect password results in a 10 second pause before being allowed to try again
    I wouldnt try too many wrond attempts though

  • Trunk vs Access Mode

    I need clarification on a trunk port.  Would you always use trunk when you are connecting to another router?  I have a ISA550 and one of the LAN ports is connected to another router's WAN port.  I have never dealt with this config so help would be appreciated.

    A trunk is used when you have the potential to be carrying multiple VLANs on a single link. If there's only a need for a single untagged VLAN between your devices, use access mode. If you need multiple VLANs or foresee the need for them in the immediate future, use trunk mode.

  • The 'Access-Control-Allow-Origin' header contains multiple values '*, *', but only one is allowed. Origin 'null' is therefore not allowed access.

    Hello. I added custom http response headers to my SP site web config file as follows: 
    <httpProtocol>
          <customHeaders>
                 <add name="Access-Control-Allow-Methods" value="POST,GET,OPTIONS" />
          <add name="Access-Control-Allow-Origin" value="*" />
          <add name="Access-Control-Allow-Headers" value="Content-Type,Authorization" />
          </customHeaders>
        </httpProtocol>
    When I try to call any web service, i get these headers two times each: 
    HTTP/1.1 200 OK
    Cache-Control: private, max-age=0
    Transfer-Encoding: chunked
    Content-Type: application/atom+xml;type=entry;charset=utf-8
    Expires: Sat, 01 Mar 2014 19:11:37 GMT
    Last-Modified: Sun, 16 Mar 2014 19:11:37 GMT
    ETag: "3"
    X-SharePointHealthScore: 0
    SPClientServiceRequestDuration: 20
    SPRequestGuid: b4e77d9c-bfc3-a050-493a-ca5d251d1a72
    request-id: b4e77d9c-bfc3-a050-493a-ca5d251d1a72
    X-FRAME-OPTIONS: SAMEORIGIN
    Persistent-Auth: true
    Access-Control-Allow-Methods: POST,GET,OPTIONS
    Access-Control-Allow-Origin: *
    Access-Control-Allow-Headers: Content-Type,Authorization
    X-AspNet-Version: 4.0.30319
    X-Powered-By: ASP.NET
    Access-Control-Allow-Methods: POST,GET,OPTIONS
    Access-Control-Allow-Origin: *
    Access-Control-Allow-Headers: Content-Type,Authorization
    MicrosoftSharePointTeamServices: 15.0.0.4569
    Date: Sun, 16 Mar 2014 19:11:37 GMT
    and that gives me error from ajax: The 'Access-Control-Allow-Origin'
    header contains multiple values '*, *', but only one is allowed. Origin 'null' is therefore not allowed access.
    The 'Access-Control-Allow-Origin' header contains multiple values '*, *', but only one is allowed.
     Origin 'null' is therefore not allowed access.
    Any idea???

    Hi Ann,
    Please check whether there are duplicate custom headers in your code.
    Similar issue for your reference:
    http://social.msdn.microsoft.com/Forums/office/en-US/b79b75f4-b46b-46ae-ae29-17a352b6b90b/custom-http-response-headers-for-sp-2013-shown-2-times?forum=sharepointdevelopment 
    Regards,
    Rebecca Tu
    TechNet Community Support

  • How to allow multiple domains under Access-Control-Allow-Origin

    Hi,
    We have a domain where will get CORS request from another domain hosted on seperate DC. We can't set
    Access-Control-Allow-Origin as * due to security concerns & IIS can't take more than 1 value at a time. Kindly suggest how to pass multiple httpheader  for
    Access-Control-Allow-Origin.
    Regards,
    Dhiraj

    Hello Dhiraj,
    This is not the suitable forum for your question, you may post in
    IIS forums for more help.
    Thanks for your understanding.
    We are trying to better understand customer views on social support experience, so your participation in this interview project would be greatly appreciated if you have time. Thanks for helping make community forums a great place.
    Click
    HERE to participate the survey.

  • How to create a calendar activity in accessibility mode ?

    I didn't find any way to create a calendar activity in accessibility mode. Since it shows blank list of days in calendar component for a month.
    It seems to be a bug in ADF calendar component. Please suggest if there is any alternate way to support this.
    Thank you so much.

    Timo,
    From a  reference doc of previous version of jdev/adf, it said :
    http://www.oracle.com/technetwork/cn/java/calendar-091799.html
    Expand the Data Controls accordion and drag the collection that represents the view object for the activity created above (FodCalEventVO) and drop it as a Calendar.
    But in Jdev 12c.--cannot find the Create Calendar choice.
    In jdev 12c can drag and drop a calendar component from the component palette, but do not now how to bind it to view objects.
    Thanks.
    BAO

  • How to change Access Mode of HANA Stored procedure

    Hi,
    When you are creating a stored procedure as design time object, one of the option is access mode (either read only or read/write).
    I understand read only is default setting in HANA DB, and unless you explicitly change the setting you cannot read/write using stored procedure.
    My question is, is there way to change this setting, so I have option to choose either read or read/write when I create a stored proc?
    Thank you.
    Hyun

    Hi Hyun,
    Please have a look on this thread:
    Create local temporary table in procedure
    You have to enable sqlscript_mode to UNSECURE as mentioned by lars.
    Then depending on whether you are specifiying "READS SQL DATA" it will act as a READ procedure else as a WRITE procedure.
    Regards,
    Krishna Tangudu

Maybe you are looking for

  • Is it possible to separate call forward unregistered & busy on a device profile?

    I've got the following situation cropping up a surprising amount at our site: User has 2 jobs within our institution. Works 3 days a week on job 1, 2 days on job 2. Each job is billed to a different cost centre, and the user doesn't want to be gettin

  • How Can I Make a Flash Animation for TV?

    I'm learning flash animation and am wondering once I save the flash file to a dvd format, how does the end-user navigate when they put the dvd into their TV? Do I need to design and incorporate a menu for the end-user? If so, how does the TV remote c

  • How to access another resource in Groupwise

    Could anyone tell me or direct me to a sample of some code, that shows how to access another resource in Groupwise with VB. The main goal is to send a appointmentsfrom another resource by accessing this resource that you have authority from own maila

  • JTextPane lineWrap at 4096. Changeable?

    JTextPane seems to be wrapping a single line after 4096 characters. I tried to look at the JTextPane/JEditorPane classes source code but cant find anything that defines that. Anyone knows where it is defined so I can set it higher? thanks.

  • Partitioning - query on large table v. query accessing several partitions

    Hi, We are using partitioning on a large fact table, however, in deciding partitioning strategy looking for advice regarding queries which have to access several partitions versus query against a large table. What is quicker - a query which acccesses