Re: IAS as RADIUS

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance




<TexasMirty@xxxxxxxxx> wrote in message
news:1157655231.145199.179300@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
You could use MAC security on the switch ports to allow only specified
devices -- specific MAC addresses. That way no one can walk in with a
laptop, "plug in" and access you network. Use "sticky" MAC address
security to make the currently-plugged in system the allowed system. If
interested, read here -


Thanks for the advice, i'm rather a fan of the ACL+ MAC filter combo,
however only on a few VLAN's can i implement this. Our engineering dept,
for instance, has customers in every week that need inet access, and surely
we can't authorize each computer everytime, it;d get to be a management
nightmare. Normally they connect to our wireless network, wich is a totally
seperate network, so there is no threat, however this weekend we had a
Korean customer come in and effectively infected 27 machines. All i can say
i thank god for backups. So one of my new project is to elimiante
unauthorized network access, this way our enigineers cant say 'oh sure just
plug in here' and have me come in to find the place in shambles monday
morning.

Im;re reveiwng my 802.1x, i was never really familiar with it anyway,
but from what i gather windows is a client (supplicant), my switches are
802.1x compliant (making them the authenticator), and im under the
impression i should be able to use IAS as my authentication server. so im
kinda back to square one, i'm thinking i might give free radius a shot just
to have something UnR here in the lab for testing and refinement. If anyone
has any idea's let me know.


.



Relevant Pages

  • Re: MAC Authentication device
    ... > network to a private network. ... Is this really advised when you can spoof MAC addresses? ... other countries) to advise their clients that internet activity will be ... > authentication server and the rest of the network as suggested above. ...
    (Security-Basics)
  • TidBITS#794/29-Aug-05
    ... This week's issue brings a potpourri of Mac news, ... Mark Anbinder looks briefly at Google Talk, ... Adding Tiger's AirPort Preferred Network List ...
    (comp.sys.mac.digest)
  • Apples new software may steal the show
    ... Steve Jobs, Apple Computer's co-founder and performer in chief, rarely shows any reluctance to sell -- or even over-sell -- his company's accomplishments. ... Jobs spent only about five minutes talking about what I see as the big news of the day: Apple's first software for using a home network through a television screen rather than a computer monitor. ... Apple's Mac OS X, the software running all its Macintosh computers, also has built-in features for easily connecting Macs in a network. ...
    (comp.sys.mac.advocacy)
  • Re: About War Driving ..
    ... However, MAC filtering does not qualify as defense in depth, ... because the attacker can spoof a valid IP address. ... broadcasting the SSID doesn't hide a network, but just makes it show up ... machines in your building that you can control and check the MAC ...
    (Security-Basics)
  • Re: Wired security improvements
    ... I have a lot of experience with 802.1x in a wireless environment and it ... option than MAC Authentication via RADIUS as far as security is concerned, ... it can only provide a weak form of network authentication. ...
    (Security-Basics)