08-31-2015 12:07 PM
I was wondering what policies other medium-large sized companies (3500 computers) actually use for port security. A recent security audit stated that we need to restrict access ports to 1 MAC to prevent people from unplugging a computer and plugging in their own device in.
But given we have 1.3 guys to manage the entire Cisco based network, it seems it would be an administrative nightmare to restrict ports at that level. Is anyone else managing a network of our size or larger actually restricting ports on a MAC level and if so how much staff is supporting this?
09-05-2015 12:41 AM
Hi,
by the huge response you have got, I take it many people do not do it.
If you use Cisco ACS, you can use 802.1x to authenticate hosts by their MAC address, this does not lock down a particular port, but allows hosts registered on the ACS to connect. to the network. so whoever is responsible for for your device setup can register the devices on ACS.
09-09-2015 06:29 PM
this may help but it does not address the administrative limitation you have. good luck!
http://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst4500/12-2/20ewa/configuration/guide/conf/port_sec.html
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide