We have a fairly
static environment and I was thinking about configuring MAC
authentication on the ports of my access switches - any drawbacks or
reasons not to?
Hi,
If you configure mac-based authentication on switches it is one of the powerful methid on L2 based authentication when ever some body plugs any laptop or desktop they would be prompted with username and password to acces the lan.
If you want to enable stingent security on LAN then you can configure 802.1x authentication on switches.Check out the below link on sample configuration on 802.1x on 6500 switches.
http://www.cisco.com/en/US/docs/switches/lan/catalyst6500/ios/12.1E/native/configuration/guide/dot1x.html
Hope to Help !!
Ganesh.H
Cisco will donate $1 to the Red Cross Haiti fund for every useful rated post!
https://supportforums.cisco.com/docs/DOC-8727