Re: Securing a LAN

From: Frank Sweetser (fs_at_erwin.wpi.edu)
Date: 12/02/04

  • Next message: David Travers: "Which is fastest program for copying files over network e.g rcp, ftp, scp, rsync"
    Date: Thu, 2 Dec 2004 00:36:06 +0000 (UTC)
    
    

    Daniel Camps <danicamps81@yahoo.com> wrote:
    > I have a LAN configured with private IP adresses and a machine doing nat to
    > go out to the Internet. I have a DHCP configured in the gateway, and I have
    > an Ethernet network. I would like to add some authentication in this
    > network, now anyone can go there plug a cable in the hub an the dhcp will
    > assign him an ip address and will be able to use the Internet, this maybe is
    > not feasible with an Ethernet but it is with a Wi-Fi access network.
    >
    > I think that with DHCP is possible to filter by MAC address only giving an
    > IP to a certain MAC, but I heard something about RADIUS, that is a server
    > used for authentication, I actually have no idea about what is a RADIUS and
    > how to configure it, but I would like some information about which are the
    > extra functionalities that RADIUS provide over a simple filtering by MAC
    > address and some clues to start learning about it.

    What you're looking for is 802.1X authentication. A google search should turn
    up ample documentation on it. Note that it's pretty uncommon for consumer
    grade ethernet switches to support 1X authentication.

    -- 
    Frank Sweetser fs at wpi.edu
    WPI Network Engineer
    GPG fingerprint = 6174 1257 129E 0D21 D8D4  E8A3 8E39 29E3 E2E8 8CEC
    

  • Next message: David Travers: "Which is fastest program for copying files over network e.g rcp, ftp, scp, rsync"

    Relevant Pages

    • Re: IP address assignment problem
      ... I have a little problem and seek for ur thoughts, let's assume I'm in a very open environment where everyone can very easily try to get his/her laptop on the network and IP addresses are assigned by a DHCP server and we are in a domain environment, how do I prevent machines that are not part of our domain to be assigned an IP address? ... This approach doesn't stop your rogue clients from connecting to other clients, but merely doesn't give them the information they normally need to do so. ... Using 802.1x, your workstations authenticate through the switch to a radius server before they are allowed any connectivity. ... This authentication can use X.509 certificates, computer account credentials from AD, or whatever else you'd normally configure radius to authenticate with. ...
      (Focus-Microsoft)
    • Re: wireless network disconnects when using IEEE 802.1x authentica
      ... since it gets encrypted before it leaves the wireless NIC ... For a home network or small ... >> Change that authentication key say every six months. ... >> RADIUS server to do that, and it works best if you've got an Active ...
      (microsoft.public.windowsxp.security_admin)
    • Re: VGER does gradual SPF activation (FAQ matter)
      ... we used to do in happy 1980es when the internet was engineer playground. ... let it send that email" - no network ACLs to keep up at all. ... With authentication done, ISP can even verify source address validity ...
      (Linux-Kernel)
    • PEAP Authentication in IAS
      ... I'm using a Procurve 2650 as Radius Client, ... Authentication in the network configuration of Windows XP and CHAP ...
      (microsoft.public.windows.server.active_directory)
    • Re: Lock down LAN
      ... When you use these switches and configure them as RADIUS clients to ... authentication fails, the client computer does not receive an IP address ... and the user cannot access the network. ... But if you have people accessing your LAN from home or other locations with ...
      (microsoft.public.internet.radius)