cancel
Showing results forĀ 
Search instead forĀ 
Did you mean:Ā 

Methods of switching security

Methods of switching security

huyckc
New Contributor II

Hello All,

I am inquiring about if anyone could help me with ideas of ways for configuring security for our switches. Currently we are looking into the ideas of Mac Based VLAN configurations and or as well as configuring Policy with Site Engine. As I am going through both of these options I can see the possible issues with either of these, but I believe there are other options that can be considered or ways to be able to mix somethings for better security. With all this we are not looking to set up a NAC and are debating on the idea of a Radius, just need to work on how to utilize this the best.

Thanks in advance for any ideas!

 

Cody 

1 REPLY 1

Steve_Ballanty1
New Contributor II

Hello Cody, I am not sure that you will get a lot of responses to this. So I can throw in my two cents.

We have been utilizing Microsoft NPA for the past few years without any problems. But this is just performing the job and actions of a RADIUS server and it sounds like you may be trying to avoid that. I can say that setting it all up is a bit tedious and took a lot of trial and error. For us, we wanted to allow a domain joined PC to join a particular network without the need for a password. And we did by using a group policy that forces domain joined PC's to obtain a device certificate with a particular server. And then a valid cert is required by the NPA server. Of course, the laptop must be a Windows device - and it must be physically connected to the network, before being placed on wireless.

But that is just one way to do it. With NPA you can define any one requirement for a host - or several. So, we could insist that our wireless users provider their active directory username and password, and then also be on a list of MAC addresses, etc.

GTM-P2G8KFN