|
Posted by Patrick Schaaf on July 15, 2005, 6:56 am
If you were Registered and logged in, you could reply and use other advanced thread options
>I need a 24 port managed Gigabit switch that can let people connect to
>the network based on their network card's MAC address. If the MAC
>address is known then it lets them connect, if the MAC address is not
>known then the switch would reject all traffic from the computer.
Are you aware that it is trivial to set the MAC address used by
an end stations to any arbitrary value? If a potential attacker
knows which MAC address is configured on a certain port, they
can disconnect the port, connect their own machine, set the
correct MAC address, and use your service without a chance
for the MAC acl to recognize the situation.
Also, with a switch in an unsecure area, nothing stops a dedicated
attacker from inserting his own switch (at lower bandwidth usage,
maybe even a dumb hub), into the uplink of your switch, circumventing
all measures configured on your switch.
best regards
Patrick
|