nicholab Posted August 25, 2023 Posted August 25, 2023 Right, what would I need network switch wise/software wise to detect unauthorized mac addresses connecting to the network?
Davit2005 Posted August 25, 2023 Posted August 25, 2023 (edited) Managed switch that you can interrogate the MAC address table on and locate the MAC address to a port. Or trace it from switch to switch if need be. Depends what switches you have how easy this is. We use iMC at the moment or do it the old fashioned way of going from switch to switch and we have 700+ switches, but we an normally track it down. Edited August 25, 2023 by Davit2005
Norphy Posted August 25, 2023 Posted August 25, 2023 (edited) That is a bad idea™. You'd have to keep a database of authorised MAC addresses, keep it up to date and contend with the fact that it's trivial to spoof a MAC Address. Plus, a lot of devices now allow you to change your MAC Address on their wireless cards to limit tracking. This isn't worth the headache. If you want to limit connections to your network to known and authorised devices, you're MUCH better off using 802.1x authentication, similar to WPAx Enterprise networks on your wireless systems. You'd have a certificate on your devices to verify their authenticity. That cert would be issued from an Enterprise CA via an MDM or by GPO. You'd have a RADIUS Server on your network to authenticate them and you'd need a switch that supports 802.1x. Can't speak for other manufacturers, but with Aruba at least, you'd need a L3 switch. Edited August 25, 2023 by Norphy 2
Davit2005 Posted August 25, 2023 Posted August 25, 2023 Might be helpful if we had the context of the question from the OP. Is this to deal with a ongoing issue or for future posibilities but yes 802.1x would be the ultimate choice as everything else has a possibility of counteracted i.e. MAC spoofing etc.
nicholab Posted August 25, 2023 Author Posted August 25, 2023 Process document that we are being audited on said that we will be alerted to unauthorized MAC addresses. We have web managed HP Procurve 1800-24G not sure if they can do what we are talking about.
dmj Posted August 25, 2023 Posted August 25, 2023 Process document that we are being audited on said that we will be alerted to unauthorized MAC addresses. Sounds like BS boxtickery to me. If you can't do it you could use that as an opportunity to get the funding to upgrade your network It sounds like it's going to be a lot of work for very little gain.
FN-GM Posted August 26, 2023 Posted August 26, 2023 Process document that we are being audited on said that we will be alerted to unauthorized MAC addresses. I would argue that it’s too late at this point. Unauthorised devices shouldn’t be getting anywhere. It’s a bit like having CCTV monitoring a unlocked door.
jmak Posted August 26, 2023 Posted August 26, 2023 Process document that we are being audited on said that we will be alerted to unauthorized MAC addresses. We have web managed HP Procurve 1800-24G not sure if they can do what we are talking about.A valuable lesson for the rest of us - unfortunately too late for you. I have fought against statements in process documents before on the basis that while it's a nice aspiration and not necessarily a bad idea, if there no realistic chance of achieving it, it can only go badly. Check your process documents and if they have something in then you know you can't do, get them changed and authorised by governors.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now