ผู้ดูแลระบบทบทวน change request กรณี 143 สำหรับระบบสำรอง ที่private cloud พบโปรไฟล์ certificate หมดอายุ policy ซ้อนกัน ประเด็น “Switching VLAN และ loop” ควรบันทึกข้อเสนอแนะใดในรายงาน
กใช้ VLAN แทน firewall ทุกกรณี
ขกำหนด access port ให้รับทุก VLAN แบบ trunk
คตรวจ VLAN tagging, access/trunk, MAC table, STP state และเส้นทางสำรอง
งต่อสายซ้ำหลายเส้นโดยปิด spanning tree
เฉลยอธิบาย
switch เรียนรู้ MAC ใน broadcast domain; VLAN แยก Layer 2 และ trunk ขนหลาย VLAN; loop ต้องควบคุมด้วยกลไกเช่น spanning tree และออกแบบ redundancy จึงเลือกข้อ C อ้างอิงมาตรฐานและเอกสารทางการปัจจุบัน ได้แก่ RFC Editor สำหรับ TCP/IP และ IPv6 https://www.rfc-editor.org/ NIST SP 800-207 เรื่อง Zero Trust https://www.nist.gov/publications/zero-trust-architecture เอกสาร Hyper-V/Windows Server รุ่นที่รองรับปัจจุบัน https://learn.microsoft.com/en-us/windows-server/virtualization/hyper-v/overview และคำอธิบาย virtual network, VLAN และ overlay https://learn.microsoft.com/en-us/windows-server/networking/sdn/manage/understanding-usage-of-virtual-networks-and-vlans