psydii Posted May 13, 2014 Posted May 13, 2014 Does anybody do this? If so what are the perils/pitfalls? It seems odd to me we put all this effort into ensuring BYOD wireless is isolated from the managed servers/clients etc, but in general speak nothing of the effects of just plugging your device into a LAN port...
pantscat Posted May 13, 2014 Posted May 13, 2014 I do this, but more from a correct/dynamic VLAN assignment point of view. Not really much in terms of perils/pitfalls - just make sure that you keep everything up to date. For example, I use the machines' AD accounts to authenticate them and this just means it's a case of putting machine accounts into the correct security group for VLAN assignment. For switch ports with printers and non 802.1x aware devices I use MAC authentication. Another option is just to use port security on the switches so that it remembers the current MAC address connected and then disables the port if any other device is connected.
cpjitservices Posted May 13, 2014 Posted May 13, 2014 This: PacketFence: Open Source NAC (Network Access Control)
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now