04-12-2023 07:26 AM
Hello,
our security department is concerned that in our office a 3rd party is able to connect to our distribution- and/or floor switch by cutting the fiber uplink and connecting to one of the 2 switches.
therefore my question is: is there any security/authentication feature available on cat9k that guarantees that nobody else can intercept the uplink? encryption comes to my mind but i expect this on extra costs.
04-12-2023 07:31 AM
there is can not done via L2 I think
instead use policy to make host in 3rd party access to specific resource other are deny.
so there is multi ACL can config here
PACL
VLAN ACL
04-12-2023 07:47 AM
There are couple ways you can do when it transit public infrastrucutre like you mentioned Dark Fibre.
You can enable MACsec between swiches, that is reason Cat 9K support that features Layer 2 MACSec
have a look below config guide :
04-12-2023 08:13 AM
i just checked out for catalyst 9200...my fear were extra costs...but it seems MACSES is already included in essentials-license.
anyway, any other ideas?
04-12-2023 08:30 AM - edited 04-12-2023 08:30 AM
"anyway, any other ideas?"
Post your question in the Security forum.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide