cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1058
Views
4
Helpful
1
Replies

Security access control per device level

wmmak
Level 1
Level 1

Dear all,

802.1x can only apply access control on user level, i.e. that user can use any pc/notebooks to gain access to network.

How about per device level? using MAC address control can be a choice, but it is not scalable as it increases admin overhead.

Is it any better method/solution out there?

Thanks a lot in advance.

mak

1 Reply 1

mike.iacovacci
Level 1
Level 1

I looked into the same thing, and found that using EAP-TLS along with Machine Certficates is a good solution, this way the "device" must have a certificate to pass the dot1x auth. The only drawback is the request,grant, and install of the certs can be daunting for a large org. Although, GPO can help if you are in a Windows AD Environment.