Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: Dynamically assign a computer in a VLAN |
|---|---|
| Date: | Thu, 21 Apr 2005 08:40:38 +0200 |
Hello Mathieu, I have made several proof of concepts with IEEE 802.1x authentication. In this procedure, a supplicant (your workstation or laptop) sends user/password credentials to an authenticator (the switch in which the VLAN exists). In the beginning, the ethernet port on which the supplicant is plugged in is in UNAUTHORIZED state (does not allow access to the LAN). The switch inserts this frames into RADIUS messages and sends them as RADIUS client to a RADIUS server (both MS IAS and Cisco Secure ACS are OK for this). If user / password are fine (according to the user database used by the RADIUS server), then the switch opens the port (switches to AUTHORIZED). Depending on the switch vendor and version, you can also send additional attributes in the RADIUS response from the server: - VLAN #: so you can dynamically assign a VLAN according to the user's identity - ACL: so you can assign an ACL at port level according to the user's identity IEEE 802.1x will only work with RADIUS towards the backend, but it is standard and broadly supported. You can also strenghthen this by adding certificates in the laptop and in the RADIUS server for encrypted authentication. Regards, Rodrigo. On 4/20/05, Mathieu RINCK <mathieu.rinck@laposte.net> wrote:
Hi everyone, We want to assign dynamically a Workstation or Laptop in a "trusted" VLAN, after authentication based on username, password and mac address. I know we can assign a computer to a VLAN with its mac address with VMPS. Can RADIUS or TACACS do the same, added with username/password authentication ? Thanks all for your answers. Mathieu Rinck
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | RE: block MSN Messenger, Gross Barry D. |
|---|---|
| Next by Date: | Re: VoIP security, Champ Clark [Vistech] |
| Previous by Thread: | Re: Dynamically assign a computer in a VLAN, Oleksandr Darchuk |
| Next by Thread: | Re: Dynamically assign a computer in a VLAN, shankarnarayan.d |
| Indexes: | [Date] [Thread] [Top] [All Lists] |