Re: Simple security

This is a discussion on Re: Simple security within the FreeRADIUS Users forums, part of the Networking and Network Related category; Hi, > Thanks Jeremy. > > I've been doing various searches for practical examples of 802.1x in a ...


Go Back   Usenet Forums > Networking and Network Related > FreeRADIUS Users

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 02-15-2007
A.L.M.Buxey@lboro.ac.uk
 
Posts: n/a
Default Re: Simple security

Hi,
> Thanks Jeremy.
>
> I've been doing various searches for practical examples of 802.1x in a LAN setting and haven't found anything yet. Have you?


it all depends on what kit you've got, both in the network space and in the server architecture.

eg with decent Cisco or HP switches you can simply enable dot1X on each switch interface and
configure the switch to RADIUS authenticate eg against FreeRADIUS. you would need to install
EAP-TLS certs on each machine - or configure PEAP etc v's an AD for auth. thats hardly 'seamless'
but no network access control is seamless to users in reality.

alternatively. how 'secure' does this have to be? you could, eg use MAC address authentication.
eg use dot1x with MAC auth...and then also do the same for DHCP. going this was you could use VMPS
on the CISCO kit - unregistered machine live on their own VLAN devoid of anything - execpt
maybe an authentication gateway to register their systems.

or, as a final option, default VLAN on the switch gives people only a captive portal. once
they have registered (or if they are already known - via MAC) a quick SNMP of their switch
port sets their vlan to the correct working one. this can be acheived with home-brew code
OR via solutions such as campus manager.

balance up the security requirements v's the cost and implementation timeframe. for a small
setup, EAP-TLS certs with real dot1x would be my personal way to go. you've just then
got the headache of those network devices that dont do dot1X - eg network printers/scanners,
voip handsets etc - for those you'd have to secure the network socket and cabling :-|

alan
-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html
Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT +1. The time now is 10:56 AM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0