> For the complete documentation index, see [llms.txt](https://trepa-technologies.gitbook.io/networking-technologies-by-johnny-bandin/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://trepa-technologies.gitbook.io/networking-technologies-by-johnny-bandin/layer-2-security/blackhole-vlan-configuration.md).

# Blackhole VLAN Configuration

#### For this How To we will configure a **"Black Hole"** VLAN. The purpose of a blackhole VLAN is to ensure that any unused and open ports are configured with a VLAN TAG/ID that does not have any network access. This means the **"Black Hole"** VLAN is not a part of any broadcast domain or subnet.

<figure><img src="https://2373667134-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F8zF1bBBRr6t1PCyfuXHu%2Fuploads%2FrcgKz49OFrJzr0XoayYd%2Flayer_2_security_network_diagram.png?alt=media&amp;token=9b445e23-b4bc-4301-8671-e1b200afa4cc" alt=""><figcaption><p>Layer 2 Security Lab Network Diagram</p></figcaption></figure>

* First we must configure the network for basic reachability. This How To assumes you already know how to configure and assign VLANs, trunks, SVIs, DHCP(Our DHCP server is a router), and DHCP relay.
* Next comes the simple configuration of a blackhole VLAN. All we do here is configure a VLAN ID that has a random number we will not use in production, and then assign that VLAN to all unused ports.

## Configuration

`SW1(config)#interface range eth0/4 - 11` # This command brings into the sub-configuration mode for a range of interfaces

`SW1(config-if-range)#switchport mode access` # This sets the switchport to access mode

`SW1(config-if-range)# switchport access vlan 888` # This sets the access VLAN to be used on the port

#### Now we must prune the **"Black Hole"** VLAN on all our trunk ports.

`SW1(config-if-range)#switchport trunk allowed vlan except 888` # This command will allow all VLANs across the trunk except for the VLAN specified

#### The full configuration is shown below.

<figure><img src="https://2373667134-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F8zF1bBBRr6t1PCyfuXHu%2Fuploads%2F0w13xZ5CcQpgmZKe5hOh%2Fblackhole%20_full_config.png?alt=media&amp;token=af45042e-c134-408b-b8d7-3ec97d1ea33f" alt=""><figcaption><p>Blackhole VLAN Configuration</p></figcaption></figure>

#### Below is a picture of all the ports on our switches we are using for demonstration.

<figure><img src="https://2373667134-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F8zF1bBBRr6t1PCyfuXHu%2Fuploads%2FlpF1np5TrZ7TVbaZuKC3%2Fshow_ip_int_br.png?alt=media&amp;token=892f9ac5-13c3-4c83-8148-1e7bbc2ec69f" alt=""><figcaption><p>show ip interface brief command</p></figcaption></figure>
