VLAN Hopping

VLAN hopping is a network attack whereby an end system sends out packets destined for a system on a different VLAN that cannot normally be reached by the end system. Typically, for a device to reach another device in a different VLAN, a Layer 3 device such as a router or Layer 3-aware switch is required. The attacker manipulates the frame and sends the traffic based on a different VLAN ID. The attacker may even attempt to be a trunk port and send 802.1q frames with data inside those frames.

Switch spoofing is a common technique whereby the attacker emulates a trunk port by using InterSwitch Link (ISL) or 802.1q frames. By using this method, the attacker can become a member of any VLAN configured in the VLAN Trunking Protocol (VTP) domain.

To mitigate this form of attack, it is highly recommended to turn off trunking on all ports that will not be enabled for Cisco ISL or the IEEE 802.1q trunking methods.

Attackers may even use a double tagging mechanism whereby the initial frame is tagged with two 802.1q frames so that when the first switch removes the header, the end device is still presented with a frame with an 802.1q header, as Figure 3-8 demonstrates.

Figure 3-8 Double Tagging 802.1q Method

802.1q, FRAME. CRC

802.1q, FRAME. CRC

First 802.1q tag removed.

Switch

Switch

Figure 3-8 shows the method of double tagging whereby the transmitted frames have two 802.1q (or ISL) headers in order to forward the frames to the wrong VLAN. The first switch to encounter the double-tagged frame (1) strips the first tag off the frame and forwards the frame. The result is that the frame is forwarded with the inner 802.1q tag out all the switch ports (2) including trunk ports configured with the native VLAN of the network attacker. The second switch then forwards the packet to the destination based on the VLAN identifier in the second 802.1q header. This enables a device in one VLAN to communicate with a device in a separate VLAN. This is an extremely vulnerable situation for your network, because now your frames do not communicate to the legitimate Layer 3 device but rather to a rouge device where all sorts of sensitive data could be compromised.

To mitigate this potential issue, all non-trunking ports should be disabled (that is, trunking is disabled) and configured as access ports or interfaces that only permit devices such as PCs or Voice over IP (VoIP) phones.

Another common technique is to disable all ports not in use on the particular switch in question. Example 3-42 displays the Catalyst OS and IOS configurations that disable trunking.

Example 3-42 Disable Trunk Ports on Catalyst OS and IOS Switches

! Catalyst OS

CatOS>(enable) set trunk mod_num/port_num off

! IOS Based switches

IOS#(config-if)switchport mode access

Continue reading here: Spanning Tree Protocol Manipulation

Was this article helpful?

+1 0

Readers' Questions

  • benilde
    What protocol should be disabled to help mitigate vlan attacks?
    1 month ago
  • To help mitigate VLAN attacks, the VLAN Trunking Protocol (VTP) should be disabled. VTP is a Cisco proprietary protocol used to propagate VLAN configuration information between switches in a network. However, it can also introduce security vulnerabilities when misconfigured or abused, potentially allowing an attacker to take control of VLANs or inject malicious configuration. By disabling VTP, it reduces the risk of unauthorized VLAN modifications or compromising the integrity of VLANs in the network.
    • Michaela
      What is a method to launch a vlan hopping attack?
      8 months ago
    • A VLAN hopping attack is a type of network attack that is used to gain access to resources in another VLAN through the exploitation of insecure network configurations. To launch a VLAN hopping attack, an attacker can use a technique called "switch spoofing," which is done by spoofing the MAC address of the switch and sending packets with a source address of the switch's port. The attacker would then send "VLAN tags" as part of the packet, which would allow the attacker to access the desired VLAN. Another technique is called "double tagging," which is done by sending two VLAN tags as part of the packet. The second tag tells the switch to send the packet to the desired VLAN, thus bypassing any security controls. The attacker could then access the network resources in the target VLAN.