Solved

Cisco: vlan access port configured with switchport mode dynamic desirable

Posted on 2013-06-28
3
939 Views
Last Modified: 2013-07-01
Can someone tell me why a port on a switch would be configured with:

interface FastEthernet 0/12
switchport access vlan 10
switchport mode dynamic desirable
end


I'm asking this because the "switchport mode dynamic desirable" is considered a security vulnerability in our scans, and I'm wondering what the risk is of removing the "switchport mode dynamic desirable" would be?

Thank you,
Dave
0
Comment
Question by:dsterling
3 Comments
 
LVL 50

Assisted Solution

by:Don Johnston
Don Johnston earned 166 total points
ID: 39286687
With the port configured as "dynamic desirable", the port will become a trunk if it can successfully negotiate with another device that is running DTP.  This is done so when a switch is connected to the port, it automatically becomes a switch. Which means that other device (usually a switch but not necessarily) would be able to communicate with all VLANs. So if it's NOT a switch, then you've just provided that device access to all your VLANs.

Forcing the port to access mode is a best practice on ports that are not connected to other switches and supposed to be trunk links.

So configuring the port with "switchport mode access" would be prudent... Unless you want it to be a trunk.
0
 
LVL 45

Accepted Solution

by:
Craig Beck earned 167 total points
ID: 39288301
Further to what donjohnston said, if you really don't want DTP on that port (or your security scan still flags it as a risk) you should use the nonegotiate command to disable DTP on that port...

interface FastEthernet 0/12
switchport access vlan 10
switchport nonegotiate
end
0
 
LVL 18

Assisted Solution

by:Akinsd
Akinsd earned 167 total points
ID: 39288723
To answer your questions.

Can someone tell me why a port on a switch would be configured with:

interface FastEthernet 0/12
switchport access vlan 10
switchport mode dynamic desirable
end

The ports were probably never fully configured aside from assigning vlans to them
All switches (at least Cisco) are configured to dynamic desirable by default. Cisco intended to make the switches usable out of the box especially for less experienced engineers.

I'm wondering what the risk is of removing the "switchport mode dynamic desirable" would be?

There is no risk removing it. It is actually safer and best practice to configure all designated ports as access ports and shutdown all unused ports.
0

Featured Post

New! My Passport Wireless Pro Wi-Fi Mobile Storage

Portable wireless storage to offload, edit, and stream anywhere.

High-capacity, wireless mobile storage designed to accompany professional photographers and videographers in the field to easily offload, edit and stream captured photos and high-definition videos.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Getting hacked is no longer a matter or "if you get hacked" — the 2016 cyber threat landscape is now titled "when you get hacked." When it happens — will you be proactive, or reactive?
Load balancing is the method of dividing the total amount of work performed by one computer between two or more computers. Its aim is to get more work done in the same amount of time, ensuring that all the users get served faster.
Here's a very brief overview of the methods PRTG Network Monitor (https://www.paessler.com/prtg) offers for monitoring bandwidth, to help you decide which methods you´d like to investigate in more detail.  The methods are covered in more detail in o…
This video gives you a great overview about bandwidth monitoring with SNMP and WMI with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're looking for how to monitor bandwidth using netflow or packet s…

920 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

12 Experts available now in Live!

Get 1:1 Help Now