03-28-2024 11:46 AM - edited 04-05-2024 10:29 AM
Hello,
I've been planning to roll out dot1x on my network. However, the network consists of NXServers in the DC with thin clients that connect back them at user desks.
As I think about it, how would dot1x work in this environment? Connecting a PC to a wall jack would get you nothing as the firmware on the thin clients connect to the NXservers. The only thing that comes to mind is MAB, but is it really worth it?
Thanks
03-28-2024 12:43 PM
There is still potential someone could connect an untrusted device into the network, with NAC enabled on the access layer switches, any random device that does not have a known MAC address and device fingerprint (learnt via profiling), could either be denied access or given a different level of access compared to your known trusted thin client devices by using TrustSec SGTs or DACLs..
03-28-2024 03:32 PM
Thanks, Rob. I'll keep this in mind as I move forward.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide