Hello, i have read many doc about this attack but there are many contradictions.
I hnow that this exploit exist in 2 ways :
Basic=> The attacker spoof a switch and gains the trunked states of the switch's port. Rely on auto-negotiate feature turned ON. This ways is simple to understand.
****************************************************************** Complex 1 => This attack is described on
1) Why the first SW accepts tagged frame but does'nt read the tags ? Is this behavior an anomaly of work ?
2) Why the last switch that receives native frame on trunk port reads the VLAN-ID ? Is this normal or anomaly ? I think that sw does'nt read VLAN-ID because the frame on trunk is native .
******************************************************************
Complex 2 => In other docs per ex:
1) The first switch read VLAN-ID on access port and forward frame on trunk ( strip off first VLAN-ID ) . This behavior is different that precedent case . Why the switch forward this frame according to VLAN-ID on the access-port ? Is this behavior another anomalies ?
******************************************************************
Sorry about lenght of post.
Thanks
Giuseppe Citerna ccie#1053
Complex 2 => This