kennysarmy Posted January 30, 2023 Posted January 30, 2023 We've had a network assessment carried out and one of the recommendations is: The school currently do not perform any authentication on the switching side for network devices connected. A recommended approach would be to look at implementing 802.1x authentication for the switching side, utilizing RADIUS this could be used to prevent any non-domain joined computers from plugging into the school’s LAN. Is this common in schools? Cheers
psydii Posted January 30, 2023 Posted January 30, 2023 I did this once "for fun" about 17 years ago. It stopped being fun quite quickly and I rolled it back. They aren't wrong... that would improve the security of your network... and good for you if that is the most effective way for you to improve your security! I do suspect though that almost every school has lower hanging fruit in that regard. 1
RLR Posted January 30, 2023 Posted January 30, 2023 We've very recently had ClearPass installed which provides network security via 802.1x and radius. It also allows onboarding for BYOD. It's was installed by a contractor and we've been left the documentation. I still need to have deep dive into to understand it better. 1
5tu Posted January 30, 2023 Posted January 30, 2023 We've very recently had ClearPass installed which provides network security via 802.1x and radius. It also allows onboarding for BYOD. It's was installed by a contractor and we've been left the documentation. I still need to have deep dive into to understand it better. Interesting. We’re also looking into this. Can I ask who you used?
FN-GM Posted January 31, 2023 Posted January 31, 2023 I have implemented it with Cisco switches and Windows Radius. Tools some work to get it right but works flawlessly once complete. Make sure you authenticate the computer accounts so there won’t any additional user authentication.
RLR Posted January 31, 2023 Posted January 31, 2023 Interesting. We’re also looking into this. Can I ask who you used? We used Switchshop. We have a guy there that has done quite a bit of work on our network so knows our setup quite well. 1
dmj Posted January 31, 2023 Posted January 31, 2023 Is this common in schools? Probably the wrong question, if you are just following other schools are doing you'll always be 10-15 yrs behind the standards. I think it's good you've got outside advice, you should follow it. FWIW at my last school we didn't do this on wired networks (we did for wireless) but we did at the University that I worked for. 2
TechMonkey Posted January 31, 2023 Posted January 31, 2023 It is one of those lines you have to decide if you (and the organisation) want to walk. An alternative is to ensure all unused ports are unpatched and any that need to stay patched are set to a default VLAN that just gets dumped out and has no access to any onsite services. It does mean an authorised device can not be connected, but how often do staff plug devices into a port, rather than connect to wi-fi, and if they do how often is it not part of a plan you are involved with? This does not prevent devices being unplugged and an attacker plugging in to that port though. You have to risk assess the likelihood and potential issues against the cost of a system to do the access control.
Davit2005 Posted January 31, 2023 Posted January 31, 2023 You can also try MAC address limits on switch ports. It would stop the majority but is a admin overhead. Personally wired 802.1x is a lot better and can be centrally managed. Implement DHCP snooping too, we've been caught out a few times, even one staff member who decided to setup a DHCP server to give out the same subnet as our dhcp server, took a few weeks to work out what the issue was, not to mention outside enginners coming on site with personal routers plugging into switches giving out dhcp or a device that decided it would be a dhcp server because it could not find one. 1
FN-GM Posted January 31, 2023 Posted January 31, 2023 You can also try MAC address limits on switch ports. This would be a security flaw. But could be hardened by locking down odd VLANS so they can only communicate to where they need to. For example ip phones only being able to connect to the PBX on the specific ports. Same with printers, CCTV etc. 1
Norphy Posted January 31, 2023 Posted January 31, 2023 We used Switchshop. We have a guy there that has done quite a bit of work on our network so knows our setup quite well. Carl Morgan?
Face-Man Posted January 31, 2023 Posted January 31, 2023 We have implemented this and it does prevent anyone bringing a device and unplugging a school computer and plugging a laptop into a network port (we had one teacher who allowed their student to bring his personal apple mac in and plug it into the network and cause a whole bunch of data protection issues). You just have to populate AD with the MAC address of every device and it works well for both wifi and cabled network .... apart for the music suit Apple mac's that keep bringing up certificate errors. 1
FN-GM Posted January 31, 2023 Posted January 31, 2023 (edited) You just have to populate AD with the MAC address of every device and it works well for both wifi and cabled network .... apart for the music suit Apple mac's that keep bringing up certificate errors. Why would you do this instead of native radius authentication? It would authenticate based on the AD computer account and you won’t be required to populate the MAC addresses. Plus mac addresses can be spoofed. Edited January 31, 2023 by FN-GM 1
Norphy Posted January 31, 2023 Posted January 31, 2023 Yep! Knows his stuff! Yes, he used to work for European Electronique and he was responsible for putting in the wireless network that the MAT I used to work for installed, plus the initial design of the network across the MAT which I adapted for the rest of it. I was pretty upset when he left them! Anyone who gets him as an engineer is damned lucky, I cannot recommend him enough.
Face-Man Posted January 31, 2023 Posted January 31, 2023 Why would you do this instead of native radius authentication? It would authenticate based on the AD computer account and you won’t be required to populate the MAC addresses. Plus Max addresses can be spoofed. Sorry it was only adding for non domain devices (printers, phones, tablets etc) we also tried it for pre-staging devices before adding to domain. We use Ruckus dynamic Vlans based on AD (username for wifi devices). You are right about spoofing MAC address but no security is perfect or 100% reliant on one layer...
RLR Posted January 31, 2023 Posted January 31, 2023 Yes, he used to work for European Electronique and he was responsible for putting in the wireless network that the MAT I used to work for installed, plus the initial design of the network across the MAT which I adapted for the rest of it. I was pretty upset when he left them! Anyone who gets him as an engineer is damned lucky, I cannot recommend him enough. Yep! We had him setup our Aruba system when he worked for EE. When we found out he left we looked on linked in to see who he was working for and contacted them.
nicholab Posted January 31, 2023 Posted January 31, 2023 Yep! We had him setup our Aruba system when he worked for EE. When we found out he left we looked on linked in to see who he was working for and contacted them. Having worked with this setup it great until a machine does not renew it certificate and then can’t get on the network. The said key person then can’t work before a fix is applied. I think the question is is it worth adding this layer of security and complexity to the network is it going to stop you doing more critical changes to security? May be it should be in your plan but lower down the list than MFA. My question would be if your network is a zero trust architecture is it needed?
computer_expert Posted January 31, 2023 Posted January 31, 2023 Having worked with this setup it great until a machine does not renew it certificate and then can’t get on the network. The said key person then can’t work before a fix is applied. At least it tells you that the machine may not be compliant with security policies or software updates if you have short cert lifetimes (e.g. a few months). In the case of laptops, then it's even better as it tells you who brings them in regularly. We changed the SSID on our wireless network in October and are still finding people who ignored the repeated emails to bring them in so they find their laptops have been cut off when they are on site. I'm all for 802.1x on the wired ports. Helps if you forget to disconnect a patch cable from the switch end...
RedwayNetworks_Michael Posted February 2, 2023 Posted February 2, 2023 Hi Guys, We find this not too common in schools mainly due to it having quite alot of management overhead adding more complexity to the network. However it is possible, if anyone would like to discuss more id be happy to put you in touch with an engineer.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now