Answer the question
In order to leave comments, you need to log in
How to implement network protection from "left" devices?
Greetings, habrosobshchestvo!
At the enterprise a network, addresses are distributed on DHCP, the Cisco switch is used. I would like to implement host control so that users cannot use their equipment (connect laptops, access points). Question is how to do it?
Can use any built-in Cisco mechanisms? Based on the deployed Radius infrastructure? And what is the best way to control? By Mac address, or something else?
In general, I am not at all special in this matter, so I will be glad for a detailed description and practical advice.
Answer the question
In order to leave comments, you need to log in
I would look towards DHCP_snooping + Option 82 DHCP+ radius as a layer between the base of subscribers and dhcp. So you get full control over all the equipment in the network, the scheme is only possible in a completely smart network. The easiest way is to deploy on the basis of any billing for ISP. Of the pluses, all poppy equipment is tied to the switch port, it will not work in another port, another poppy will not work in this port, etc. individual ACLs for any centrally managed device. It works like this, the first time the device is connected to the network, it receives a special fake address from which only the authorization page is available, enters its login password, the device is recorded in the account of a specific subscriber and receives all its filtering rules, etc. Cons - expensive for iron. Outline the problem in full, maybe something simpler will suit.
As I understand it, you need to dig towards using IEEE 802.1X technology . She is just friends with the Radius server. Alas, I can’t tell you more about the setting, because. I have purely theoretical knowledge in this area. It will be interesting to observe the answers of more competent specialists.
At my last job it was like this:
habrahabr.ru/post/124697/
(A colleague just wrote the article)
Look towards the port security function Port security . There you can restrict the connection of third-party devices by MAC addresses and configure the switch's response to this event
Everything is simple. Set up a shared network. The first network is only workplaces, which organized access to the Internet. The second network is only the internal network. Next, the dhcp server must know the computers to which it issued addresses, and if it knows everyone, then check the box or switch to the position - prohibit the connection of unknown clients. The second shared network is all the others. Unknown clients must be allowed to connect. Send them to the stub. You can bind everything to networks and poppies manually.
In fact, Windows has a special role for these purposes - Network Access Protection.
And she will destroy everything on the basis of 802.1X.
Didn't find what you were looking for?
Ask your questionAsk a Question
731 491 924 answers to any question