Articles

ANALYSIS OF PROTECTION EFFECTIVENESS AGAINST DOUBLE TAGGING ATTACKS IN HETEROGENEOUS NETWORK ENVIRONMENTS (CISCO, MIKROTIK, ELTEX)

Download PDF Article on eLIBRARY.RU

Abstract

This paper presents a practical analysis of a VLAN Hopping attack implemented using the Double Tagging technique, which allows attackers to bypass the logical isolation of virtual local area networks based on the IEEE 802.1Q standard. The study examines architectural characteristics of VLAN technology related to native VLAN processing on trunk ports of Ethernet switches that create conditions for exploiting Layer 2 vulnerabilities. The mechanism of forming Ethernet frames with double 802.1Q tagging is described in detail, along with the frame forwarding logic that allows such packets to be delivered into a target VLAN segment without authorization.

The experimental part of the research was conducted on a dedicated testbed using real network equipment from multiple vendors, including Cisco, MikroTik, and Eltex. This heterogeneous environment allows evaluation of device behavior under identical attack conditions. The Yersinia utility was used to generate Ethernet frames with double tagging, while network traffic was captured and analyzed using the tcpdump tool to confirm successful delivery of traffic to a protected VLAN segment.

The study compares device behavior under default configurations and after applying standard security countermeasures. The results demonstrate that the default native VLAN configuration on trunk ports makes network infrastructures vulnerable to Double Tagging attacks regardless of the equipment vendor. Based on the experimental findings, practical recommendations for improving VLAN-based network segmentation security are proposed, including assigning a non-default native VLAN, explicitly configuring port modes, and disabling automatic trunk negotiation mechanisms. The research highlights the critical importance of correct Layer 2 configuration practices for ensuring secure segmentation in modern heterogeneous network environments.

Online viewer

References

  1. IEEE Standard 802.1Q-2018 - Bridges and Bridged Networks [Электронный ресурс] // IEEE Standards Association. – 2018. – URL: https://standards.ieee.org/standard/802_1Q-2018.html (дата обращения: 15.12.2025).
  2. Cisco Systems, Inc. Understanding and Configuring VLAN Trunk Protocol (VTP) // Cis-co Technical Documentation. – 2023. – URL: https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst2960/software/release/12-2_55_se/configuration/guide/scg_2960/swvtp.html (дата обращения: 15.12.2025).
  3. Уймин, А. Г. Компьютерные сети. L2-технологии : практикум для СПО / А. Г. Уй-мин. — Саратов ; Москва : Профобразование, Ай Пи Ар Медиа, 2024. — 190 c. — ISBN 978-5-4497-2559-2. — Текст : электронный // Цифровой образовательный ресурс IPR SMART: [сайт]. — URL: https://www.iprbookshop.ru/135231.html (дата обращения: 13.12.2025).
  4. Convery, S. Hacking Layer 2: Fun with Ethernet Switches // Black Hat USA 2002. – 2002. – URL: https://blackhat.com/presentations/bh-usa-02/bh-us-02-convery-switches.pdf (дата обращения: 11.12.2025).
  5. Knobbe, F. VLAN Security // SANS Institute InfoSec Reading Room. – 2002. – URL: https://www.sans.org/reading-room/whitepapers/protocols/vlan-security-853 (дата обращения: 12.12.2025).
  6. SANS Institute. Network Penetration Testing Survey 2023 [Электронный ресурс] // SANS Survey Report. - 2023. - URL: https://www.sans.org/reading-room/whitepapers/survey/network-penetration-testing-survey-2023-39845 (дата обращения: 12.12.2025)
  7. MikroTik Documentation. VLAN Security and Bridge Filtering // MikroTik Official Doc-umentation. – 2024. – URL: https://help.mikrotik.com/docs/display/ROS/VLAN (дата обращения: 14.12.2025).

License

Copyright (c) 2025 L. G. Khoroshilov , N. A. Kostin (Authors))

Keywords