Re: My "wire" / not yours

From: S. Pidgorny (slavickp_at_yahoo.com)
Date: 03/23/05


Date: Wed, 23 Mar 2005 20:34:26 +1100

There can be many devices using same MAC address. That allows to bypass DHCP
security, and in some cases 802.1x and proprietary switch port security
solutions:

http://sl.mvps.org/docs/802dot1x.htm

-- 
Svyatoslav Pidgorny, MS MVP - Security, MCSE
-= F1 is the key =-
"Sylvie" <sylviep@videotron.net> wrote in message
news:uL0jvo1LFHA.1180@TK2MSFTNGP14.phx.gbl...
> In the end it comes down to this : some switches (probably all by now)
allow
> you to set the port to accept only one MAC address. You do not have to set
> the MAC address that you want to enable. The switch will accept the first
> one and refuse all others. We use this configuration to prevent users from
> connecting hubs and switches or unauthorized computer. The problem with
this
> is that you will have to clear the port config when you want another
> computer to connect to the port.
>
> Sorry I do not know the protocol or the RFC but I know that Cisco 2900
> series switches can do it.
>


Relevant Pages

  • Re: Its War!
    ... they know which port is doing what. ... Once they have that MAC address, ... security seriously, they have tied your MAC address to you. ... log into the router for Internet, the mere fact that you can get ...
    (microsoft.public.windowsxp.general)
  • Re: Down with DHCP!!!!
    ... static IPs. ... your assumption about security is flawed. ... handle mac-based port security. ... or you can set up a RADIUS server with a database of authorized MAC ...
    (Security-Basics)
  • RE: How to find a changing IP on ethernet network
    ... called "port security". ... tell it how many MAC ... to issue an SMTP trap to your Network Management ...
    (Security-Basics)
  • Re: Static IP outside of router DHCP range
    ... Unfortunately my 8 clients are little $50 boxes with an Ethernet port and yellow, red, and white outputs for composite NTSC video and stereo audio, but no provisions whatsoever to flash their NVRAM. ... So I have no way to either reserve IP addresses based on Mac addresses, nor do I have a way to set them up as static. ... I still am wondering if my Netgear switches truly have any "memory" of the ports associated with specific IP addresses of the connected clients, as they have no reset or reboot function as far as I know. ...
    (alt.comp.hardware.pc-homebuilt)
  • Re: ROGUE APs at Work - How to locate them?!
    ... If you have the MAC address and you have ethernet switches that are smart ... MAC address, then you lookup that MAc address on the switches until you find ... the hardware port. ... network card in the PC could unplug the computer, ...
    (alt.internet.wireless)

Quantcast