RE: DHCP security

From: Payton, Zack (Zack.Payton_at_MWAA.com)
Date: 10/11/05

  • Next message: John Williams: "OS to know."
    Date: Tue, 11 Oct 2005 15:00:07 -0400
    To: <razk@smarteam.com>, <security-basics@securityfocus.com>
    
    

    802.1X is a nice switch level protocol that enables one to restrict the
    activation of a switchport based on any number of criteria via the
    Extensible Authentication Protocol (EAP) and it's family of relatives.
    This suite enables one to restrict access based on any imaginable set of
    criteria including MAC address, username, machine name, certificate,
    etc.
    The option which you mentioned is (at least in the cisco world) referred
    to as port security. This option will allow frames sourced only from
    certain MAC adddresses to enter the switch. 802.1x is very simple to
    deploy, works cross platform/cross vendor, and offers a plethora of
    extentions that you can use including centralized management by
    connecting on the backend to a radius/tacacs server.

    Z

    -----Original Message-----
    From: razk@smarteam.com [mailto:razk@smarteam.com]
    Sent: Monday, October 10, 2005 3:38 AM
    To: security-basics@securityfocus.com
    Subject: DHCP security

    hello

    i am looking for a solution of restricting unauthorised MAC addresses to
    be able to connect into our LAN. (Visitors etc.) our main concern is
    that we have around 50 new VmWares coming up everyday and our network is
    flat without any vlans so we can't realy put them in a seperate network.

    i was introduced to a solution on the port level of the switch but was
    wandering if there are any other solutions.

    thanks.

    Raz.


  • Next message: John Williams: "OS to know."

    Relevant Pages

    • VMWare if_em breakage (was: Re: svn commit: r194865 - in head/sys: dev/e1000 modules/igb)
      ... pointer to the HW structure ... 82574L Gigabit Network Connection ... switch { ... * Enables replication of broadcast and multicast packets from the network ...
      (freebsd-current)
    • Re: Switch Statements and Refactoring
      ... map nicely to a single Key like switch statements, ... if it meets the criteria... ... in which case you may not care which type ... >> and execute a switch on all of the subs. ...
      (comp.object)
    • Re: implimenting select...Case
      ... Search = Switch(_ ... > This works fine except that ive got 7 queries for the rowsource of Result ... 'find all the students in a building ... > Its going to get worse cos ive been told that further criteria will be ...
      (microsoft.public.access.formscoding)
    • Re: ALTERNATIVE TO SUMPRODUCT NEEDED
      ... You can use DCOUNT by setting the criteria text to *switch*. ... switch will occur in a paragraph, so I need a wild card and SUMPRODUCT ...
      (microsoft.public.excel.worksheet.functions)
    • Re: Scheduled Task - defrag.exe
      ... I can't find the switch that enables the "Stop the task if ... the computer ceases to be idle" check box. ... XP results in "command line parameter not recognised". ... that there isn't such a switch for XP ...
      (microsoft.public.windowsxp.perform_maintain)