Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations SkipVought on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Network Security

Status
Not open for further replies.

BigJammer

IS-IT--Management
Mar 3, 2004
7
0
0
US
I've been tasked with locking down our network so that only authorized company pc's/laptops can run on the network. This eliminates vendors and home pc's from connecting to the network, possibly launching viruses, etc.
I've came up with a couple solutions:
1. Integrating 802.1x technology on our switches, end nodes and Cisco Secure server. More or less if you don't authenticate through Cisco Secure, your port doesn't get turned on.
2. MAC filtering through Cisco Secure. If your mac isn't in the database, you can't get on. This may be a huge undertaking and is extremely micro-managed, as well as may cause login times to be very slow.

Anyone else have any other suggestions?

 
If you have a switch with EMI IOS installed, you can try combination of layer 3 access-list together with setting up static mac addresses or switch port-security.

Peter Mesjar
CCNP, A+ certified
pmesjar@centrum.sk

"The only true wisdom is in knowing you know nothing.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top