• 4 Posts
  • 1.33K Comments
Joined 2 years ago
cake
Cake day: November 14th, 2023

help-circle
  • I’ll try an analogy to explain better. The firewall is a lock on the door to your house. Vlans are a rule that to go from one room to another, you must go back out the locked door and back in.

    So an attacker tries to come in and can’t pick the lock. You are safe.

    Another attacker can pick the lock and get into a room. But if they can pick the lock for one room, they can pick the same lock again and get into any other rooms because it’s the same lock protecting every room in the house.



  • if you allowed that to happen you either did not set firewall rules strict enough

    The argument was that the vlans force a device through the firewall so that the firewall can protect it. But for that to happen, like you said the firewall wasn’t strick enough or didn’t have a defense against a 0 day.

    So the vlan doesn’t do anything either way. Either the firewall works in which case you don’t need vlans to force local traffic through them a second time or they don’t work in which case again the vlan did nothing.