RE: Network "Change Management"

From: Evan Pierce (evan_at_pierce.co.za)
Date: 09/16/04

  • Next message: okeeffe_at_xecu.net: "Re: Network "Change Management""
    To: "'Dave  Torre'" <dtorre@fostercity.org>, <focus-linux@securityfocus.com>
    Date: Thu, 16 Sep 2004 23:15:23 +0200
    
    

    Dave

    Why not rather restrict DHCP to an allowed list of MAC addresses? And lock a
    specific port onto a specific MAC address or if you have too many users that
    are mobile (plug into many different ports) use EAP or 802.1x authentication
    from the switch to a Radius server and block things that way. Most modern
    switches will allow this.

    Thanks
    Evan

    -----Original Message-----
    From: Dave Torre [mailto:dtorre@fostercity.org]
    Sent: 14 September 2004 07:53 PM
    To: focus-linux@securityfocus.com
    Subject: Network "Change Management"

    Does anyone know of a Linux utility that can watch the MAC address tables in
    Cisco switches and alert admins as to when a new device has been plugged in?

    Basically, we have your standard client network with DHCP. Internet access
    is restricted to authenticated users, and so are the file shares.
    However, we've had a few instances where people just plug in their personal
    laptops which makes me very worried...

    Any thoughts/suggestions as to how I can monitor such events in real time?

    Thanks,
    -Dave


  • Next message: okeeffe_at_xecu.net: "Re: Network "Change Management""

    Relevant Pages

    • Re: ROGUE APs at Work - How to locate them?!
      ... If you have the MAC address and you have ethernet switches that are smart ... MAC address, then you lookup that MAc address on the switches until you find ... the hardware port. ... network card in the PC could unplug the computer, ...
      (alt.internet.wireless)
    • Re: How to block a client from DHCP?
      ... server, and compliant operating systems. ... Another option is to use switches that can protect the network based on mac ... My HP2512 switch also can do port isolation ...
      (microsoft.public.windows.server.networking)
    • Re: Network scanning
      ... HP managed switches have this feature too, as a bonus you can also specify ... simultanious MACs on a port, or specify which addresses are allowed. ... Subject: Network scanning ... Most newer switches can lock down how many mac addresses are allowed to ...
      (Security-Basics)
    • Re: Seeing unexpected skinny heartbeats when sniffing IP phones network traffic
      ... :supposedly a normal occurance when the switches MAC table gets filled ... :its table, it sends it out all its ports; not as a broadcast packet, ... :but essentially a broadcast because it is sent out every port. ...
      (comp.dcom.sys.cisco)
    • Re: IP address conflicts
      ... I'm about the 4th or 5th successor to this network. ... > have to go without since we don't have the money for new switches" ... You need to be able to query the mac table in the switch ... > to see what port that address is coming in from. ...
      (freebsd-questions)