Re: Port Security on switches?



Sounds like you're looking for 802.1x enabled networking gear:

http://en.wikipedia.org/wiki/802.1X

How well it works/easy it is to manage depends on the gear you're using.
Most implementations have provisions for allowing unauthenticated
systems (such as vendors, visitors, or contractors) to have some form of
network access.

-
Abe Getchell
me@xxxxxxxxxxxxxxx
http://abegetchell.com/


On Fri, 2008-03-14 at 13:21 -0500, Albert R. Campa wrote:
Do you use it? Is it a good idea network wide? Yes I guess it could be
an administrative pain but I want to see how it is used these days.

Is there an alternative?

My concern is people connecting non authorized laptops to the network
and getting an IP then access. What is a common/effective way to be
notified of any new device connected to the network?

Sure we have physical security(guards 24/7) in our main building,
badge access security in our other building, but visitors such as
vendors, contractors, etc come often and its basically left up to
their sponsors to ensure they dont connect anything to a free port on
the wall.

Comments are appreciated.

Albert



Relevant Pages

  • RE: IDSIPS that can handle one Gig
    ... I am not contending your performance figures - 5000 connections per second ... is quite a reasonable amount to assume on your average enterprise network, ... a bit of a bun fight when you place two vendors side by side and ... What is important, however, is the number of packets per second the device ...
    (Focus-IDS)
  • RE: IDSIPS that can handle one Gig
    ... is quite a reasonable amount to assume on your average enterprise network, ... a bit of a bun fight when you place two vendors side by side and ... What is important, however, is the number of packets per second the device ... Find out quickly and easily by testing it with real-world attacks from CORE ...
    (Focus-IDS)
  • RE: Strange domain-udp signature
    ... It may be common practice for some vendors... ... passive techniques ... "statically map" the network to determine the optimal path. ... world's premier technical IT security event! ...
    (Incidents)
  • Re: Providing Visitor Access
    ... only authorized vendors are allowed to use this restricted VLAN. ... They have to sign the same agreement to use our network as any employee, ... looking at just providing a DSL connection that is not connected to our ...
    (Security-Basics)
  • RE: NIPS Vendors explicit answer
    ... this is the only comprehensive independent IPS test that's been ... Make sure the product continues to block attacks when simple, ... Test the IPS like you would any other network element (switch, ... The other vendors waiting for my tests:) are Netscreen IDP,RealSecure ISS Proventia G200 and Network Associates NAI Intruvert 2600 series. ...
    (Focus-IDS)

Quantcast