ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    802.1x port-based authentication - when and why?

    IT Discussion
    802.1x switch authentication
    10
    34
    2.7k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • DonahueD
      Donahue
      last edited by

      I dont know about you guys, but I worry a lot more about accident stupidity than targeted attacks.

      dafyreD 1 Reply Last reply Reply Quote 0
      • dafyreD
        dafyre @Donahue
        last edited by

        @donahue said in 802.1x port-based authentication - when and why?:

        I dont know about you guys, but I worry a lot more about accident stupidity than targeted attacks.

        Often both result in the same ending, lol.

        Rather than overcomplicating my network, I'd rather just keep unused ports disabled. Ideally, there would at least a couple of folks on my team who know how to enable and disable ports as needed.

        1 Reply Last reply Reply Quote 1
        • DashrenderD
          Dashrender @Obsolesce
          last edited by

          @obsolesce said in 802.1x port-based authentication - when and why?:

          @jaredbusch said in 802.1x port-based authentication - when and why?:

          @obsolesce said in 802.1x port-based authentication - when and why?:

          It's not just protecting against malicious actors. It could be to make sure employees aren't bringing in their own devices and putting them onto the LAN, bypassing external protections.

          That is a malicious actor.

          Stupidity or ignorance doesn't mean malicious.

          I'm going to have to go with JB on this one.

          ObsolesceO 1 Reply Last reply Reply Quote 0
          • DashrenderD
            Dashrender
            last edited by

            The whole disabling ports seems like a waste of time. If someone wants on the network, they'll simply unplug a printer and plug in. They know that line is live. Or they will unplug their own computer, again, they know it's live.

            crustachioC 1 Reply Last reply Reply Quote 0
            • ObsolesceO
              Obsolesce @Dashrender
              last edited by

              @dashrender said in 802.1x port-based authentication - when and why?:

              @obsolesce said in 802.1x port-based authentication - when and why?:

              @jaredbusch said in 802.1x port-based authentication - when and why?:

              @obsolesce said in 802.1x port-based authentication - when and why?:

              It's not just protecting against malicious actors. It could be to make sure employees aren't bringing in their own devices and putting them onto the LAN, bypassing external protections.

              That is a malicious actor.

              Stupidity or ignorance doesn't mean malicious.

              I'm going to have to go with JB on this one.

              Malicious is defined as intent to do harm, which is why I disagree. If the intent is not there, it's not malicious.

              DashrenderD JaredBuschJ 2 Replies Last reply Reply Quote 0
              • DashrenderD
                Dashrender @Obsolesce
                last edited by

                @obsolesce said in 802.1x port-based authentication - when and why?:

                @dashrender said in 802.1x port-based authentication - when and why?:

                @obsolesce said in 802.1x port-based authentication - when and why?:

                @jaredbusch said in 802.1x port-based authentication - when and why?:

                @obsolesce said in 802.1x port-based authentication - when and why?:

                It's not just protecting against malicious actors. It could be to make sure employees aren't bringing in their own devices and putting them onto the LAN, bypassing external protections.

                That is a malicious actor.

                Stupidity or ignorance doesn't mean malicious.

                I'm going to have to go with JB on this one.

                Malicious is defined as intent to do harm, which is why I disagree. If the intent is not there, it's not malicious.

                LOL - now that's a Scott answer if there ever was one. 😛

                ObsolesceO scottalanmillerS 2 Replies Last reply Reply Quote 0
                • JaredBuschJ
                  JaredBusch @Obsolesce
                  last edited by

                  @obsolesce said in 802.1x port-based authentication - when and why?:

                  @dashrender said in 802.1x port-based authentication - when and why?:

                  @obsolesce said in 802.1x port-based authentication - when and why?:

                  @jaredbusch said in 802.1x port-based authentication - when and why?:

                  @obsolesce said in 802.1x port-based authentication - when and why?:

                  It's not just protecting against malicious actors. It could be to make sure employees aren't bringing in their own devices and putting them onto the LAN, bypassing external protections.

                  That is a malicious actor.

                  Stupidity or ignorance doesn't mean malicious.

                  I'm going to have to go with JB on this one.

                  Malicious is defined as intent to do harm, which is why I disagree. If the intent is not there, it's not malicious.

                  If you are plugging something in to a company asset that you wer enot told to do, you are intentionally doing something. Shit doens't plug itself it. Shit does not bring itself into the office.

                  1 ObsolesceO 2 Replies Last reply Reply Quote 0
                  • 1
                    1337 @JaredBusch
                    last edited by

                    @jaredbusch said in 802.1x port-based authentication - when and why?:

                    If you are plugging something in to a company asset that you were not told to do, you are intentionally doing something. Shit doesn't plug itself it. Shit does not bring itself into the office.

                    That reminds me of something. When you set up 802.1x on a windows computer, is it the user account that is logged in that you are authenticating or is it the computer itself or both?

                    coliverC 1 Reply Last reply Reply Quote 0
                    • ObsolesceO
                      Obsolesce @JaredBusch
                      last edited by

                      @jaredbusch said in 802.1x port-based authentication - when and why?:

                      @obsolesce said in 802.1x port-based authentication - when and why?:

                      @dashrender said in 802.1x port-based authentication - when and why?:

                      @obsolesce said in 802.1x port-based authentication - when and why?:

                      @jaredbusch said in 802.1x port-based authentication - when and why?:

                      @obsolesce said in 802.1x port-based authentication - when and why?:

                      It's not just protecting against malicious actors. It could be to make sure employees aren't bringing in their own devices and putting them onto the LAN, bypassing external protections.

                      That is a malicious actor.

                      Stupidity or ignorance doesn't mean malicious.

                      I'm going to have to go with JB on this one.

                      Malicious is defined as intent to do harm, which is why I disagree. If the intent is not there, it's not malicious.

                      If you are plugging something in to a company asset that you wer enot told to do, you are intentionally doing something. Shit doens't plug itself it. Shit does not bring itself into the office.

                      If company policy says to not plug that stuff into the network, and you do so anyways, then yes, I'll agree that is malicious.

                      1 Reply Last reply Reply Quote 0
                      • ObsolesceO
                        Obsolesce @Dashrender
                        last edited by Obsolesce

                        @dashrender said in 802.1x port-based authentication - when and why?:

                        @obsolesce said in 802.1x port-based authentication - when and why?:

                        @dashrender said in 802.1x port-based authentication - when and why?:

                        @obsolesce said in 802.1x port-based authentication - when and why?:

                        @jaredbusch said in 802.1x port-based authentication - when and why?:

                        @obsolesce said in 802.1x port-based authentication - when and why?:

                        It's not just protecting against malicious actors. It could be to make sure employees aren't bringing in their own devices and putting them onto the LAN, bypassing external protections.

                        That is a malicious actor.

                        Stupidity or ignorance doesn't mean malicious.

                        I'm going to have to go with JB on this one.

                        Malicious is defined as intent to do harm, which is why I disagree. If the intent is not there, it's not malicious.

                        LOL - now that's a Scott answer if there ever was one. 😛

                        What is this:
                        0_1539725734201_2debdb78-e681-4bd4-b844-9802e3b8db4a-image.png

                        JaredBuschJ 1 Reply Last reply Reply Quote 0
                        • JaredBuschJ
                          JaredBusch @Obsolesce
                          last edited by

                          @obsolesce 0_1539726406725_910021a8-d76f-481f-9c63-79d635c08b75-image.png

                          ObsolesceO 1 Reply Last reply Reply Quote 0
                          • ObsolesceO
                            Obsolesce @JaredBusch
                            last edited by

                            @jaredbusch said in 802.1x port-based authentication - when and why?:

                            @obsolesce 0_1539726406725_910021a8-d76f-481f-9c63-79d635c08b75-image.png

                            Odd, i wonder why they don't show up for me

                            1 Reply Last reply Reply Quote 0
                            • coliverC
                              coliver @1337
                              last edited by

                              @pete-s said in 802.1x port-based authentication - when and why?:

                              @jaredbusch said in 802.1x port-based authentication - when and why?:

                              If you are plugging something in to a company asset that you were not told to do, you are intentionally doing something. Shit doesn't plug itself it. Shit does not bring itself into the office.

                              That reminds me of something. When you set up 802.1x on a windows computer, is it the user account that is logged in that you are authenticating or is it the computer itself or both?

                              Depends on how you set it up. But Windows is able to do both User and Computer authentication.

                              1 Reply Last reply Reply Quote 1
                              • scottalanmillerS
                                scottalanmiller @Dashrender
                                last edited by

                                @dashrender said in 802.1x port-based authentication - when and why?:

                                @obsolesce said in 802.1x port-based authentication - when and why?:

                                @dashrender said in 802.1x port-based authentication - when and why?:

                                @obsolesce said in 802.1x port-based authentication - when and why?:

                                @jaredbusch said in 802.1x port-based authentication - when and why?:

                                @obsolesce said in 802.1x port-based authentication - when and why?:

                                It's not just protecting against malicious actors. It could be to make sure employees aren't bringing in their own devices and putting them onto the LAN, bypassing external protections.

                                That is a malicious actor.

                                Stupidity or ignorance doesn't mean malicious.

                                I'm going to have to go with JB on this one.

                                Malicious is defined as intent to do harm, which is why I disagree. If the intent is not there, it's not malicious.

                                LOL - now that's a Scott answer if there ever was one. 😛

                                @dashrender said in 802.1x port-based authentication - when and why?:

                                @obsolesce said in 802.1x port-based authentication - when and why?:

                                @dashrender said in 802.1x port-based authentication - when and why?:

                                @obsolesce said in 802.1x port-based authentication - when and why?:

                                @jaredbusch said in 802.1x port-based authentication - when and why?:

                                @obsolesce said in 802.1x port-based authentication - when and why?:

                                It's not just protecting against malicious actors. It could be to make sure employees aren't bringing in their own devices and putting them onto the LAN, bypassing external protections.

                                That is a malicious actor.

                                Stupidity or ignorance doesn't mean malicious.

                                I'm going to have to go with JB on this one.

                                Malicious is defined as intent to do harm, which is why I disagree. If the intent is not there, it's not malicious.

                                LOL - now that's a Scott answer if there ever was one. 😛

                                It was THAT good.

                                But he's right, accidents are not malicious. However, we've discussed malicious before, and "willing to do harm" seems to fit within the definition, when someone willingly puts the business at risk for personal gain. It's not that the goal is the harm, but they harm willingly to further their ends.

                                A true accident would be if they had no idea they weren't supposed to do it or that they were doing it (like they knocked the cable off a desk and it plugged itself in as it fell.)

                                DonahueD 1 Reply Last reply Reply Quote 0
                                • DonahueD
                                  Donahue @scottalanmiller
                                  last edited by

                                  @scottalanmiller said in 802.1x port-based authentication - when and why?:

                                  ...(like they knocked the cable off a desk and it plugged itself in as it fell.)

                                  This feels like it should be a meme of some sort.

                                  scottalanmillerS 1 Reply Last reply Reply Quote 1
                                  • scottalanmillerS
                                    scottalanmiller @Donahue
                                    last edited by

                                    @donahue said in 802.1x port-based authentication - when and why?:

                                    @scottalanmiller said in 802.1x port-based authentication - when and why?:

                                    ...(like they knocked the cable off a desk and it plugged itself in as it fell.)

                                    This feels like it should be a meme of some sort.

                                    Someone tell XKCD 😉

                                    1 Reply Last reply Reply Quote 1
                                    • DonahueD
                                      Donahue
                                      last edited by

                                      how to get him on ML?

                                      scottalanmillerS 1 Reply Last reply Reply Quote 1
                                      • scottalanmillerS
                                        scottalanmiller @Donahue
                                        last edited by

                                        @donahue said in 802.1x port-based authentication - when and why?:

                                        how to get him on ML?

                                        Now that would be awesome!

                                        Paging Randall Munroe

                                        1 Reply Last reply Reply Quote 1
                                        • crustachioC
                                          crustachio @Dashrender
                                          last edited by

                                          @dashrender said in 802.1x port-based authentication - when and why?:

                                          The whole disabling ports seems like a waste of time. If someone wants on the network, they'll simply unplug a printer and plug in. They know that line is live. Or they will unplug their own computer, again, they know it's live.

                                          This is actually the real power of 802.1x. It can do more than just toggle a switchport on/off. If you tie your 802.1x implementation to a policy manager/access server, you can dynamically assign VLANs and/or ACLs to that switchport.

                                          So that printer is live on the network because it matches certain criteria (certificate, predefined MAC whitelist, device fingerprint, etc), but if someone unplugs it and plugs their laptop in the same port it no longer matches and is blackholed (or gets whatever policy you wish). Same with swapping your LAN PC for a BYOD laptop. The traditional "port tagged as VLAN xyz" can't protect you in this situation, but a policy-based 802.1x implementation gives you total control.

                                          Of course you need a NAC server of some kind to be able to achieve this, but in the spirit of the OP, 802.1x can do quite a lot more than just basic switchport toggling.

                                          Also, it's commonly relied on for WiFi access control. When you consider any WiFi network that touches the LAN as essentially an invisible switch that anyone can touch without physical access restrictions, then 802.1x auth starts to look pretty attractive.

                                          DashrenderD 1 Reply Last reply Reply Quote 3
                                          • DashrenderD
                                            Dashrender @crustachio
                                            last edited by

                                            @crustachio said in 802.1x port-based authentication - when and why?:

                                            @dashrender said in 802.1x port-based authentication - when and why?:

                                            The whole disabling ports seems like a waste of time. If someone wants on the network, they'll simply unplug a printer and plug in. They know that line is live. Or they will unplug their own computer, again, they know it's live.

                                            This is actually the real power of 802.1x. It can do more than just toggle a switchport on/off. If you tie your 802.1x implementation to a policy manager/access server, you can dynamically assign VLANs and/or ACLs to that switchport.

                                            So that printer is live on the network because it matches certain criteria (certificate, predefined MAC whitelist, device fingerprint, etc), but if someone unplugs it and plugs their laptop in the same port it no longer matches and is blackholed (or gets whatever policy you wish). Same with swapping your LAN PC for a BYOD laptop. The traditional "port tagged as VLAN xyz" can't protect you in this situation, but a policy-based 802.1x implementation gives you total control.

                                            Of course you need a NAC server of some kind to be able to achieve this, but in the spirit of the OP, 802.1x can do quite a lot more than just basic switchport toggling.

                                            Also, it's commonly relied on for WiFi access control. When you consider any WiFi network that touches the LAN as essentially an invisible switch that anyone can touch without physical access restrictions, then 802.1x auth starts to look pretty attractive.

                                            Assuming you're doing this for your switches as well, you also need switches that support that, I have no clue at what price point those become available.

                                            JaredBuschJ scottalanmillerS 2 Replies Last reply Reply Quote 0
                                            • 1
                                            • 2
                                            • 2 / 2
                                            • First post
                                              Last post