11-11-2020 10:58 AM
APs are mostly authenticated at a switchport to use an automatic configuration of switchport behaviours (VLANs, port authentication, ..) like I mentioned in my “AP-Aware” idea. We need this function as well for authentication and automation to connect access switches to core/distribution/fabric switches. This ist for security reasons in case of using distributed switches in office, production, IOT/OT, … to prevent unauthorized usage uf the uplink ports as well as a basic function to use automation in a distributed environment.
This is not new to use a 802.1X supplicant on access devices (like APs) to connect to switchports and use automation for on-/offboarding.
More and more small devices in production, healthcare, education environments for headless devices, IOT/OT force us to deliver an easy to deploy and use environment.
br
Volker
03-23-2021 12:41 PM
Better to use MacSec
03-19-2021 04:06 PM
Gents,
let’s look forward into the future, not back into the past. HP does it because they have nothing else to do, they missed entire fabric play and BTW now are trying to chase it.
Choosing between implementing 802.1x supplicant and Auto-Sensing feature I'd better have latter.
In the picture from HP manual - what is real world use case? Switch A in uncontrolled environment, where anyone can plug/unplug uplink, and concern is that malicious user can gain access to uplink traffic ? But 802.1x doesn’t solve it. Perhaps HP/Aruba lied to customer about it, but in reality I just need little hub between SwA and SwB - and here you go, I have access to all traffic !
What we can do on EXOS to have similar level of protection - LLDP. configure custom LLDP data, and use UPM port to block port unless you see proper string in LLDP.
But it’s a kludge of course, you should use MACSEC if customer is really concerned about security.
01-21-2021 03:50 PM
Hello,
since this feature is missing we have just failed to replace 140 HP switches with XOS switches. HP (now Aruba) has supported this feature for years.
Specifically, this is a project where Fiber to the Desk is in use and therefore there is a switch in every office. To prevent an employee from being on the network after unplugging the switch, authentication must also be performed on the uplink, not just on the access.
Here a screenshot from the HP manual
And NO VSP is no option here in the moment for the customer.
12-22-2020 02:55 PM
Volker, auto-sense does exactly that:
Roger