Re: Q: Controlling access at the Ethernet level

From: Gleb Smirnoff (glebius_at_cell.sick.ru)
Date: 04/04/04

  • Next message: Bill Vermillion: "Re: News Server"
    Date: Sun, 4 Apr 2004 23:32:52 +0400
    To: Adrian Penisoara <ady@freebsd.ady.ro>
    
    

    On Sun, Apr 04, 2004 at 09:22:33PM +0300, Adrian Penisoara wrote:
    A> We have thought about using static MAC entries per port on managed
    A> switches installed at the client endpoints, but that would require a
    A> overwhelming budget. We are also thinking about L2TP and PPPoE, but I
    A> am uncertain about compatibility.

    PPPoE is a working solution. mpd from ports can serve PPPoE at wirespeed.
    However is has some disadvantages:
    - Traffic from host A to host B flows thru access concentrator.
    - All hosts share bandwidth of access concentrator
    - mpd in PPPoE mode does not work under CURRENT
    - PPPoE gives authentication for access outside your LAN, it does not
      prevent someone plugging into a port of dumb switch and flooding your
      LAN with broadcasts, or performing any other kind of ethernet DoS.

    A> I also heard about 802.1x technology and seems to be an interesting
    A> and professional alternative; I just don't know how well supported is
    A> on the server side, namely FreeBSD.

    Theoretically, 802.1x is best solution. But client side is supported only in
    Windows XP, and I've been told that it has numerous weird bugs. In 802.1x
    the server side is ethernet switch itself, which authenticates clients
    on RADIUS server. So upgrading all switches in your LAN is required. The
    cheapest one with 802.1x support is D-Link DES-3226, AFAIK.

    -- 
    Totus tuus, Glebius.
    GLEBIUS-RIPN GLEB-RIPE
    _______________________________________________
    freebsd-isp@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-isp
    To unsubscribe, send any mail to "freebsd-isp-unsubscribe@freebsd.org"
    

  • Next message: Bill Vermillion: "Re: News Server"

    Relevant Pages

    • Re: DHCP Strangest Problem I ever Seen in my life
      ... I debuged the switches and ... transmitting the DHCP discover etc? ... > 100 MB port fast ... DHCPDiscover (from client) ...
      (microsoft.public.win2000.networking)
    • Re: DHCP Strangest Problem I ever Seen in my life
      ... Catalyst 3550 all the ports in all the switches are set to full duplex and ... 100 MB port fast ... network and the clients don't send a single packet to the dhcp, ... > DHCPDiscover (from client) ...
      (microsoft.public.win2000.networking)
    • Re: NIDS Recommendations in limited environment...
      ... switches these days support port mirroring (I don't think you just got ... There are many client PC's manned by any number of people. ... cannot provide proper monitoring functions. ...
      (Focus-IDS)
    • Re: Client Access Dropped Sessions ... imagine that!
      ... They are installing from a cd that has V5R2 CA (or iSeries Access as they now call it). ... My client has an iSeries 820 we did have a 10mb David Express Managed Hub which I gave them several years ago. ... We decided to get them up to speed with 100mb switches, so we did the change out and put in a couple of rackmount 24 port switches from TrendNet. ... The dropped sessions ONLY happen on machines that run "dual" sessions and it is happening regardless of operating system or machine specs. ...
      (comp.sys.ibm.as400.misc)
    • RE: Network scanning
      ... > be sourced on one port.. ... > plenty of cisco switches that do this anyhow, ... > Wenn Sie nicht der richtige Adressat sind oder diese E-Mail irrtümlich ... > informieren Sie bitte sofort den Absender und vernichten Sie diese Mail. ...
      (Security-Basics)

    Loading