Posts

Showing posts with the label Network Access Control

Guest and BYOD Wireless: Isolation, Onboarding and Per-User Keys

Guest and personal-device wireless is where network design meets the fact that you do not control the endpoint. The question is not how to secure those devices — you cannot — but how to give them the access they need while ensuring a compromised one reaches nothing that matters. Guest networks A guest network should provide internet access and nothing else. Getting that right means three things. Segmentation. Guest traffic goes into its own VLAN with no route to internal networks, enforced by access control lists rather than by the absence of a route — routes appear. Give it its own DHCP scope and DNS, and do not let guest clients resolve internal names. Client isolation. Guests should not reach each other either. Without it, one infected laptop scans and attacks every other device on the guest network, which in a hotel or conference setting is a substantial population. Wireless client isolation is a single setting on most controllers and is frequently left off....

802.1X Port-Based Authentication: Supplicant, Authenticator, and RADIUS

802.1X authenticates a device before it is allowed to pass traffic on a switch port or wireless network. Until authentication succeeds the port carries nothing but the authentication exchange itself, which means an unauthorized device plugged into a conference room jack reaches nothing at all. It is the foundation of network access control and a reliable exam topic. The three roles The supplicant is software on the connecting device that presents credentials. Every modern operating system includes one. The authenticator is the switch or wireless access point controlling the port. It does not decide anything; it relays the conversation and enforces the verdict by opening or keeping the port closed. The authentication server is a RADIUS server holding the policy and the credential store, usually backed by a directory. It makes the decision and returns it, optionally with attributes telling the authenticator which VLAN to assign or which access list to apply. The separation matt...