05-06-2013 10:50 PM - edited 03-07-2019 01:13 PM
my point is with port base security concern in which I have imposed mac base security on all access port, now if some one know the allowed mac he or she can static assign mac to laptop/PC and access to network.
This is security lack, please advice anything we can do this to mitigate
Solved! Go to Solution.
05-07-2013 03:53 PM
Hello Fahad,
You are right, but with port security you have allowed mac-addresses on certain ports so you assume that user with that MAC will be connected to particular port. If someone steal MAC address to other user, attacker needs to also connect to correct port to have access to network.
If you are still concern about security, you can additionaly implement port based authentication ->
http://www.cisco.com/en/US/docs/ios/12_4t/12_4t11/ht_8021x.html
Best Regards
Please rate all helpful posts and close solved questions
05-07-2013 03:53 PM
Hello Fahad,
You are right, but with port security you have allowed mac-addresses on certain ports so you assume that user with that MAC will be connected to particular port. If someone steal MAC address to other user, attacker needs to also connect to correct port to have access to network.
If you are still concern about security, you can additionaly implement port based authentication ->
http://www.cisco.com/en/US/docs/ios/12_4t/12_4t11/ht_8021x.html
Best Regards
Please rate all helpful posts and close solved questions
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide