networking-forum.com
Community BlogCommunity Wiki * Register  * Search  * Login
View unanswered postsView active topics

All times are UTC - 6 hours [ DST ]



Post new topic Reply to topic  [ 2 posts ] 
Author Message
PostPosted: Wed May 30, 2012 6:03 pm 
Offline
New Member
New Member

Joined: Fri May 18, 2012 6:57 pm
Posts: 3
Certs: CCNA
Hey network experts,

I have a very simple problem, but due to my lack of knowledge, I don't know where to start. Now, before I go into the details, let me say that I don't expect a full solution from anyone on the forum, just a sign as to where the next step might be would be greatly appreciated.

Goal
I want to secure access to my network and it's resources (servers, users). Basically, I don't want anyone to get an IP address that I haven't given out (as a result of successful authentication) and I want to drop any traffic from IP addresses that I haven't assigned.

Current Layout
Customers---> APs (which I cannot control, but the users are isolated from each other) ---> Layer 2 unmanageable switches ---> Layer 3 managed switch ---> Internet
It can be assumed that servers to support authentication (RADIUS/TACACS+) are inserted off of the layer 3 switch.

What I've looked at
802.1X authentication. But, from what I understand, 802.1X drops all other traffic from the port while negotiations are taking place, so I don't think that would be practical for my situation, since I have multiple users using a single port. Does that mean that the only possible solution is to get new APs?

Captive portal. But I believe those are inherently insecure, since an attacker could hypothetically spoof your captive portal and redirect customers. Is this the only security risk?

Thank you for your time,
Seanny


Top
 Profile  
 
PostPosted: Thu May 31, 2012 1:08 am 
Online
Post Whore
Post Whore
User avatar

Joined: Thu Dec 30, 2010 2:05 pm
Posts: 1123
Location: Stockholm, SE
Certs: CCNP, CCNP SP, CCDA, CCNA DC, CCNA W, HP MASE
Im not sure if you've looked at using 802.1x at the switchport connected to the AP (since the "multiple users using a single port" remark) or at the AP itself? How are the users authenticated in the AP today?

I would definatelly look at some APs you can control and deploy .1x on them as a first step, second there is also 802.1x wired if you have wired users.

Also to secure your DHCP you should deploy DHCP snooping where applicable.

_________________
som om sinnet hade svartnat för evigt.


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 2 posts ] 

All times are UTC - 6 hours [ DST ]


Who is online

Users browsing this forum: No registered users and 9 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB® Forum Software © phpBB Group