Re: Mac to VLAN mapping on Cisco switches
- From: Doug McIntyre <merlyn@xxxxxxxxx>
- Date: 12 May 2012 04:22:05 GMT
Martijn Lievaart <m@xxxxxxxxxxxxxxxx> writes:
We are looking at ways to ease management of VLANs, and secure on basis
of MAC address (yes I know, easily spoofed).
After much googling, it seems that:
- 802.1x has the potential to do what we want, but always needs a
supplicant (agent) on the connecting device. As too many devices we use
(a.o. thin clients) do not have this capability, this is out for now[1].
Am I correct that for MAC based 802.1x vlan assignment, one always needs
an agent on the device?
Most modern OSs have this built into the networking stack.
Ie. Windows7/Mac OSX/Linux all do. I can't tell about your thin clients.
- The other option would be VMPS. Open Source software can get the MAC/
VLAN assignment from a database[2], but can Cisco software do similar? Do
they even have a dedicated VMPS server, or is one stuck with downloading
a file to the master switches?
VMPS was never fully supported by Cisco in the first place. Rumor was
that some large customer wanted a solution (this was long before .1x)
and cisco half-heartedly built something in. The VMPS server ran in
a 6500 switch, there never was general server code outside of switch hardware..
To say it is insecure is an understatement. Sniff, spoof and any VLAN
hopping instantly done.
Since .1x, whatever supported level of VMPS existed vanished, and it
is kept around mainly in the platforms that had it just in a holding pattern.
But, are you over generalizing this as a solution? There haven't been
many locations where I'd even consider .1x. To me, it is a specialized
solution to begin with.
It all sounds neat, just edit radius to assign VLAN, but in reality,
it is even easier to keep track of switch ports and edit which
VLAN a given switch port is in and hard code it there. No security
issues, no having to run extra stuff. I'd say 99.99% of the situations
in which I find myself that this is the standard setup.
keeping track of switch ports is easier than dealing with usernames
and passwords.
.
- References:
- Mac to VLAN mapping on Cisco switches
- From: Martijn Lievaart
- Mac to VLAN mapping on Cisco switches
- Prev by Date: Mac to VLAN mapping on Cisco switches
- Next by Date: Questions about Networking
- Previous by thread: Mac to VLAN mapping on Cisco switches
- Next by thread: Questions about Networking
- Index(es):
Relevant Pages
|