Jump to content

Who implements 802.1x authentication for their fixed networks utilizing RADIUS?


Recommended Posts

Posted

We've had a network assessment carried out and one of the recommendations is:

 

 

The school currently do not perform any authentication on the switching side for network devices

connected. A recommended approach would be to look at implementing 802.1x authentication for

the switching side, utilizing RADIUS this could be used to prevent any non-domain joined

computers from plugging into the school’s LAN.

 

 

Is this common in schools?

 

Cheers

Posted

I did this once "for fun" about 17 years ago. It stopped being fun quite quickly and I rolled it back.

 

They aren't wrong... that would improve the security of your network... and good for you if that is the most effective way for you to improve your security! I do suspect though that almost every school has lower hanging fruit in that regard.

  • Thanks 1
Posted
We've very recently had ClearPass installed which provides network security via 802.1x and radius. It also allows onboarding for BYOD. It's was installed by a contractor and we've been left the documentation. I still need to have deep dive into to understand it better.
  • Thanks 1
Posted
We've very recently had ClearPass installed which provides network security via 802.1x and radius. It also allows onboarding for BYOD. It's was installed by a contractor and we've been left the documentation. I still need to have deep dive into to understand it better.

 

Interesting. We’re also looking into this. Can I ask who you used?

Posted
I have implemented it with Cisco switches and Windows Radius. Tools some work to get it right but works flawlessly once complete. Make sure you authenticate the computer accounts so there won’t any additional user authentication.
Posted
Interesting. We’re also looking into this. Can I ask who you used?

 

We used Switchshop. We have a guy there that has done quite a bit of work on our network so knows our setup quite well.

  • Thanks 1
Posted

Is this common in schools?

 

Probably the wrong question, if you are just following other schools are doing you'll always be 10-15 yrs behind the standards. I think it's good you've got outside advice, you should follow it.

FWIW at my last school we didn't do this on wired networks (we did for wireless) but we did at the University that I worked for.

  • Thanks 2
Posted

It is one of those lines you have to decide if you (and the organisation) want to walk. An alternative is to ensure all unused ports are unpatched and any that need to stay patched are set to a default VLAN that just gets dumped out and has no access to any onsite services. It does mean an authorised device can not be connected, but how often do staff plug devices into a port, rather than connect to wi-fi, and if they do how often is it not part of a plan you are involved with?

 

This does not prevent devices being unplugged and an attacker plugging in to that port though. You have to risk assess the likelihood and potential issues against the cost of a system to do the access control.

Posted

You can also try MAC address limits on switch ports. It would stop the majority but is a admin overhead. Personally wired 802.1x is a lot better and can be centrally managed.

 

Implement DHCP snooping too, we've been caught out a few times, even one staff member who decided to setup a DHCP server to give out the same subnet as our dhcp server, took a few weeks to work out what the issue was, not to mention outside enginners coming on site with personal routers plugging into switches giving out dhcp or a device that decided it would be a dhcp server because it could not find one.

  • Thanks 1
Posted
You can also try MAC address limits on switch ports.

 

This would be a security flaw. But could be hardened by locking down odd VLANS so they can only communicate to where they need to. For example ip phones only being able to connect to the PBX on the specific ports. Same with printers, CCTV etc.

  • Thanks 1
Posted

We have implemented this and it does prevent anyone bringing a device and unplugging a school computer and plugging a laptop into a network port (we had one teacher who allowed their student to bring his personal apple mac in and plug it into the network and cause a whole bunch of data protection issues).

You just have to populate AD with the MAC address of every device and it works well for both wifi and cabled network .... apart for the music suit Apple mac's that keep bringing up certificate errors.

  • Thanks 1
Posted (edited)

You just have to populate AD with the MAC address of every device and it works well for both wifi and cabled network .... apart for the music suit Apple mac's that keep bringing up certificate errors.

 

Why would you do this instead of native radius authentication? It would authenticate based on the AD computer account and you won’t be required to populate the MAC addresses.

 

Plus mac addresses can be spoofed.

Edited by FN-GM
  • Thanks 1
Posted
Yep! Knows his stuff!

 

Yes, he used to work for European Electronique and he was responsible for putting in the wireless network that the MAT I used to work for installed, plus the initial design of the network across the MAT which I adapted for the rest of it. I was pretty upset when he left them!

 

Anyone who gets him as an engineer is damned lucky, I cannot recommend him enough.

Posted
Why would you do this instead of native radius authentication? It would authenticate based on the AD computer account and you won’t be required to populate the MAC addresses.

 

Plus Max addresses can be spoofed.

 

Sorry it was only adding for non domain devices (printers, phones, tablets etc) we also tried it for pre-staging devices before adding to domain. We use Ruckus dynamic Vlans based on AD (username for wifi devices).

 

You are right about spoofing MAC address but no security is perfect or 100% reliant on one layer...

Posted
Yes, he used to work for European Electronique and he was responsible for putting in the wireless network that the MAT I used to work for installed, plus the initial design of the network across the MAT which I adapted for the rest of it. I was pretty upset when he left them!

 

Anyone who gets him as an engineer is damned lucky, I cannot recommend him enough.

 

Yep! We had him setup our Aruba system when he worked for EE. When we found out he left we looked on linked in to see who he was working for and contacted them.

Posted
Yep! We had him setup our Aruba system when he worked for EE. When we found out he left we looked on linked in to see who he was working for and contacted them.

 

Having worked with this setup it great until a machine does not renew it certificate and then can’t get on the network. The said key person then can’t work before a fix is applied.

 

I think the question is is it worth adding this layer of security and complexity to the network is it going to stop you doing more critical changes to security?

 

May be it should be in your plan but lower down the list than MFA.

 

My question would be if your network is a zero trust architecture is it needed?

Posted
Having worked with this setup it great until a machine does not renew it certificate and then can’t get on the network. The said key person then can’t work before a fix is applied.

 

At least it tells you that the machine may not be compliant with security policies or software updates if you have short cert lifetimes (e.g. a few months).

 

In the case of laptops, then it's even better as it tells you who brings them in regularly. We changed the SSID on our wireless network in October and are still finding people who ignored the repeated emails to bring them in so they find their laptops have been cut off when they are on site.

 

I'm all for 802.1x on the wired ports. Helps if you forget to disconnect a patch cable from the switch end...

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...