2 June 1999 - 802.1 - Coeur d’Alene 1
IEEE 802.1
Port-based Network Access Control
Jeff Hayes Product Manager - Xylan jeff.hayes@xylan.com
IEEE 802.1 Port-based Network Access Control Jeff Hayes Product - - PowerPoint PPT Presentation
IEEE 802.1 Port-based Network Access Control Jeff Hayes Product Manager - Xylan jeff.hayes@xylan.com 1 2 June 1999 - 802.1 - Coeur dAlene Network Access Control What? $XWKHQWLFDWHG $XWKHQWLFDWHG 8VHUV 8VHUV distributed
2 June 1999 - 802.1 - Coeur d’Alene 1
Jeff Hayes Product Manager - Xylan jeff.hayes@xylan.com
2 June 1999 - 802.1 - Coeur d’Alene 2
$XWKHQWLFDWLRQ $XWKHQWLFDWLRQ 6HUYHU 6HUYHU $XWKHQWLFDWHG $XWKHQWLFDWHG 8VHUV 8VHUV
– distributed security – authenticate users at the switch port – once authenticated,
– leverage common authentication systems
directory servers
switch
2 June 1999 - 802.1 - Coeur d’Alene 3
– Perimeter security
edge
– Not all users created equal
– Not all networks created equal
access control measures
2 June 1999 - 802.1 - Coeur d’Alene 4
Authentication Authentication Server Server Authenticated Authenticated Users Users
– distributed user authentication
– user mobility with campus setting – leveraged by single sign-on systems
switch switch switch
2 June 1999 - 802.1 - Coeur d’Alene 5
– user authentication in enterprises
– network ingress security
– key verticals are ideal for switch access control
2 June 1999 - 802.1 - Coeur d’Alene 6
6DWHOOLWH &DPSXV
&DPSXV %DFNERQH
$XWKHQWLFDWLRQ 6HUYHU
'HSDUWPHQWDO 6XEQHWV $FFHVV &RQWURO
Goal – authenticated open Goal – authenticated open computing computing
– central campus, satellites & dorms
– students - dorms, classrooms & library – faculty - offices & classes – admin - offices
2 June 1999 - 802.1 - Coeur d’Alene 7 Patient Records & Accounting Research Hospital
Goal – patient & research Goal – patient & research confidentiality confidentiality
– in/out patient hospital – research labs
– MDs, nurses, admins – research Phds & techs
– authenticate into key subnets – filter / firewall internal traffic
2 June 1999 - 802.1 - Coeur d’Alene 8
ISP 1 ISP 2 ISP 3
Goal Goal – secure, multi-layer secure, multi-layer Internet access Internet access
– via DSL or cable
NSP’s POP
– RADIUS – multiple authorities – one user per switch port
sourced services
– separate billing
2 June 1999 - 802.1 - Coeur d’Alene 9
– No authentication needed for inter-switch ports
– not all switch ports must be authenticated ports
– re-authenticate according to policy
– authenticator can request more information before determining the mechanism – smart cards, Kerberos, PKI, 1-time pswd, etc.
2 June 1999 - 802.1 - Coeur d’Alene 10
– some want a MAC-based option = more control – authenticate into authorized VLAN = choice – client does DHCP after authentication
– same look & feel regardless of campus location – mixed vendor enviro=common user experience – many users need both non-auth access and auth access, depending on local port
2 June 1999 - 802.1 - Coeur d’Alene 11
authentication
– all or nothing / open or closed
authentication
– VLAN membership control (IP unicast, IP multicast, IPX, AT, etc.)
2 June 1999 - 802.1 - Coeur d’Alene 12
access authentication method is required
definite need for this capability
– extra layer of security at the network edge
implement, do not discount the control layer-2 mechanisms offer