I have a network, where a have a couple of VLANS. There is a firewall between the 2 VLANs. I am using HP Procurve switches and have made sure that switch-to-switch links accept tagged frames only and that host ports don't accept tagged frames (They are not "VLAN Aware"). I've also made sure that the trunk ports don't have a native VLAN. I've also enabled "Ingress Filtering". Furthermore, I've made sure that host ports are only members of a single VLAN, which is the same as the PVID of the respective port. The only ports which are members of multiple VLANs are the trunk ports.
Can someone please explain to me why the above isn't secure? I believe I've addressed the double tagging issue..
Update: Both switches are Hp Procurve 1800-24G
This question was IT Security Question of the Week.
Read the Apr 20, 2012 blog entry for more details or submit your own Question of the Week.