<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: 802.1x and Malware Identification in Wireless</title>
    <link>https://community.cisco.com/t5/wireless/802-1x-and-malware-identification/m-p/5470911#M292497</link>
    <description>&lt;P&gt;Several thoughts.&lt;/P&gt;&lt;P&gt;1. You could get the SOC to monitor the APs and the firewall.  Then they'll be able to see clients.&lt;/P&gt;&lt;P&gt;2. You are probably using SSID NAT mode.  If you create a dedicated VLAN for guests, and bridge the SSID to that VLAN they'll be able to see the individual clients on the firewall.&lt;/P&gt;</description>
    <pubDate>Tue, 14 Jan 2025 21:10:09 GMT</pubDate>
    <dc:creator>Philip D'Ath</dc:creator>
    <dc:date>2025-01-14T21:10:09Z</dc:date>
    <item>
      <title>802.1x and Malware Identification</title>
      <link>https://community.cisco.com/t5/wireless/802-1x-and-malware-identification/m-p/5470903#M292489</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;I'm new to networking and recently started with a new company. I haven't been able to get an answer to this, so I thought I'd try here.&lt;/P&gt;&lt;P&gt;My understanding is that because we use 802.1x and have to configure each AP's IP address on our firewall, when our SOC identifies malware on an endpoint, they can only see the AP's IP address. So if there's, say, 10-20 devices on the AP, there's no way to know exactly which device needs to be remediated.&lt;/P&gt;&lt;P&gt;1. Is this a common implementation? It seems...not great, from a security perspective. &lt;/P&gt;&lt;P&gt;2. Are there any alternatives with our current infrastructure, or would the solution be to move away from 802.1x to something like FortiNAC?&lt;/P&gt;&lt;P&gt;3. Did anything that I just said make any sense, or should I change careers (again)?&lt;/P&gt;&lt;P&gt;I appreciate your time.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jan 2025 13:36:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/802-1x-and-malware-identification/m-p/5470903#M292489</guid>
      <dc:creator>Ryan20241</dc:creator>
      <dc:date>2025-01-14T13:36:31Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1x and Malware Identification</title>
      <link>https://community.cisco.com/t5/wireless/802-1x-and-malware-identification/m-p/5470904#M292490</link>
      <description>&lt;P&gt;I believe they are monitoring incorrectly, regardless of whether the client is on Wi-Fi or wired network, they should be able to identify the source of the alert.&lt;/P&gt;&lt;P&gt;I believe they should correct the monitoring.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jan 2025 14:21:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/802-1x-and-malware-identification/m-p/5470904#M292490</guid>
      <dc:creator>aleabrahao</dc:creator>
      <dc:date>2025-01-14T14:21:51Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1x and Malware Identification</title>
      <link>https://community.cisco.com/t5/wireless/802-1x-and-malware-identification/m-p/5470905#M292491</link>
      <description>&lt;P&gt;By the way, I don't know how you are monitoring but Trellix can be a great ally in these cases.&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.trellix.com/" target="_blank" rel="nofollow noopener noreferrer"&gt;https://www.trellix.com/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jan 2025 14:43:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/802-1x-and-malware-identification/m-p/5470905#M292491</guid>
      <dc:creator>aleabrahao</dc:creator>
      <dc:date>2025-01-14T14:43:55Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1x and Malware Identification</title>
      <link>https://community.cisco.com/t5/wireless/802-1x-and-malware-identification/m-p/5470906#M292492</link>
      <description>&lt;P&gt;If you are using NAT mode for your wireless clients on any of your ssids, then any upstream device will only see the traffic as sourcing from the AP so this is entirely possible, although it has nothing to do with 802.1x. That functionality can work with or without NAT mode.&lt;BR /&gt;&lt;BR /&gt;You can change your ssids to drop off to a VLAN the firewall can fully see to alleviate the issue.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jan 2025 14:48:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/802-1x-and-malware-identification/m-p/5470906#M292492</guid>
      <dc:creator>mloraditch</dc:creator>
      <dc:date>2025-01-14T14:48:59Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1x and Malware Identification</title>
      <link>https://community.cisco.com/t5/wireless/802-1x-and-malware-identification/m-p/5470907#M292493</link>
      <description>&lt;P&gt;In this case it makes sense.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jan 2025 15:39:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/802-1x-and-malware-identification/m-p/5470907#M292493</guid>
      <dc:creator>aleabrahao</dc:creator>
      <dc:date>2025-01-14T15:39:51Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1x and Malware Identification</title>
      <link>https://community.cisco.com/t5/wireless/802-1x-and-malware-identification/m-p/5470908#M292494</link>
      <description>&lt;P&gt;Thank you - I'll reach out to our SOC for clarification.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jan 2025 15:49:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/802-1x-and-malware-identification/m-p/5470908#M292494</guid>
      <dc:creator>Ryan20241</dc:creator>
      <dc:date>2025-01-14T15:49:18Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1x and Malware Identification</title>
      <link>https://community.cisco.com/t5/wireless/802-1x-and-malware-identification/m-p/5470909#M292495</link>
      <description>&lt;P&gt;I just double-checked, and we do have NAT mode enabled on our SSIDs. Do you know of any major drawbacks or pitfalls to transitioning off of this?&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jan 2025 16:02:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/802-1x-and-malware-identification/m-p/5470909#M292495</guid>
      <dc:creator>Ryan20241</dc:creator>
      <dc:date>2025-01-14T16:02:10Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1x and Malware Identification</title>
      <link>https://community.cisco.com/t5/wireless/802-1x-and-malware-identification/m-p/5470910#M292496</link>
      <description>&lt;P&gt;The biggest disadvantage is that in NAT mode, client devices will always use the AP's IP to communicate with any resource.&lt;/P&gt;&lt;P&gt;If you need to monitor client IPs, use bridge mode.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jan 2025 16:25:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/802-1x-and-malware-identification/m-p/5470910#M292496</guid>
      <dc:creator>aleabrahao</dc:creator>
      <dc:date>2025-01-14T16:25:45Z</dc:date>
    </item>
    <item>
      <title>Re: 802.1x and Malware Identification</title>
      <link>https://community.cisco.com/t5/wireless/802-1x-and-malware-identification/m-p/5470911#M292497</link>
      <description>&lt;P&gt;Several thoughts.&lt;/P&gt;&lt;P&gt;1. You could get the SOC to monitor the APs and the firewall.  Then they'll be able to see clients.&lt;/P&gt;&lt;P&gt;2. You are probably using SSID NAT mode.  If you create a dedicated VLAN for guests, and bridge the SSID to that VLAN they'll be able to see the individual clients on the firewall.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jan 2025 21:10:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/wireless/802-1x-and-malware-identification/m-p/5470911#M292497</guid>
      <dc:creator>Philip D'Ath</dc:creator>
      <dc:date>2025-01-14T21:10:09Z</dc:date>
    </item>
  </channel>
</rss>

