contrafack VLAN это просто метка в пакете, комутатор в зависимости от настроек может принять пакет без изменений, перемаркировать или вообще отбросить.
Умолчальная политика большинства свичей - без тэга маркировать нативным, остальные пропускать. Т.е. если не зафильтровать то можно тэгироваными пакетами достучаться до других вланов, включая управление.
Добавлено: Цитата: а можно пример неполной настройки?
Куски конфига:
[more=неполная]
vlan 21
name User
normal ""
fixed 1-26
forbidden ""
untagged 1-24
exit
vlan 100
name MGMT
normal 1-24
fixed 25-26
ip address default-management 1.2.3.5 255.255.255.0
ip address default-gateway 1.2.3.254
exit
interface port-channel 1
pvid 21
bmstorm-limit
loopguard
exit
interface port-channel 2
pvid 21
bmstorm-limit
loopguard
exit
interface port-channel 3
pvid 21
bmstorm-limit
loopguard
exit
interface port-channel 4
pvid 21
bmstorm-limit
loopguard
exit
interface port-channel 5
pvid 21
bmstorm-limit
loopguard
exit
interface port-channel 6
pvid 21
bmstorm-limit
loopguard
exit
interface port-channel 7
pvid 21
bmstorm-limit
loopguard
exit
interface port-channel 8
pvid 21
bmstorm-limit
loopguard
exit
interface port-channel 9
pvid 21
bmstorm-limit
loopguard
exit
interface port-channel 10
pvid 21
bmstorm-limit
loopguard
exit
interface port-channel 11
pvid 21
bmstorm-limit
loopguard
exit
interface port-channel 12
pvid 21
bmstorm-limit
loopguard
exit
interface port-channel 13
pvid 21
bmstorm-limit
loopguard
exit
interface port-channel 14
pvid 21
bmstorm-limit
loopguard
exit
interface port-channel 15
pvid 21
bmstorm-limit
loopguard
exit
interface port-channel 16
pvid 21
bmstorm-limit
loopguard
exit
interface port-channel 17
pvid 21
bmstorm-limit
loopguard
exit
interface port-channel 18
pvid 21
bmstorm-limit
loopguard
exit
interface port-channel 19
pvid 21
bmstorm-limit
loopguard
exit
interface port-channel 20
pvid 21
bmstorm-limit
loopguard
exit
interface port-channel 21
pvid 21
bmstorm-limit
loopguard
exit
interface port-channel 22
pvid 21
bmstorm-limit
loopguard
exit
interface port-channel 23
pvid 21
bmstorm-limit
loopguard
exit
interface port-channel 24
pvid 21
bmstorm-limit
loopguard
exit
storm-control
loopguard
[/more]
[more=полная]
vlan 21
name User
normal ""
fixed 1-26
forbidden ""
untagged 1-24
exit
vlan 100
name MGMT
normal ""
fixed 25-26
forbidden 1-24
untagged 1-24
ip address default-management 1.2.3.5 255.255.255.0
ip address default-gateway 1.2.3.254
exit
interface port-channel 1
pvid 21
bmstorm-limit
loopguard
exit
interface port-channel 2
pvid 21
bmstorm-limit
loopguard
exit
interface port-channel 3
pvid 21
bmstorm-limit
loopguard
exit
interface port-channel 4
pvid 21
bmstorm-limit
loopguard
exit
interface port-channel 5
pvid 21
bmstorm-limit
loopguard
exit
interface port-channel 6
pvid 21
bmstorm-limit
loopguard
exit
interface port-channel 7
pvid 21
bmstorm-limit
loopguard
exit
interface port-channel 8
pvid 21
bmstorm-limit
loopguard
exit
interface port-channel 9
pvid 21
bmstorm-limit
loopguard
exit
interface port-channel 10
pvid 21
bmstorm-limit
loopguard
exit
interface port-channel 11
pvid 21
bmstorm-limit
loopguard
exit
interface port-channel 12
pvid 21
bmstorm-limit
loopguard
exit
interface port-channel 13
pvid 21
bmstorm-limit
loopguard
exit
interface port-channel 14
pvid 21
bmstorm-limit
loopguard
exit
interface port-channel 15
pvid 21
bmstorm-limit
loopguard
exit
interface port-channel 16
pvid 21
bmstorm-limit
loopguard
exit
interface port-channel 17
pvid 21
bmstorm-limit
loopguard
exit
interface port-channel 18
pvid 21
bmstorm-limit
loopguard
exit
interface port-channel 19
pvid 21
bmstorm-limit
loopguard
exit
interface port-channel 20
pvid 21
bmstorm-limit
loopguard
exit
interface port-channel 21
pvid 21
bmstorm-limit
loopguard
exit
interface port-channel 22
pvid 21
bmstorm-limit
loopguard
exit
interface port-channel 23
pvid 21
bmstorm-limit
loopguard
exit
interface port-channel 24
pvid 21
bmstorm-limit
loopguard
exit
vlan1q ingress-check
storm-control
loopguard
[/more]
Разница небольшая но в первом случае я могу например добраться до VLAN'а управления из пользовательского порта.
Это такой упрощенный пример без извратных настроек фильтрации.