Home > Security Tips > Network Security Tactics > The X Factor: 802.1X keeps intruders off your network
Security Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

NETWORK SECURITY TACTICS

The X Factor: 802.1X keeps intruders off your network


Diana Kelley
09.04.2003
Rating: -4.00- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


You've heard a lot about how the 802.1X protocol is designed to close a yawning security gap, particularly for wireless traffic. But it also provides added security for your wired networks. Strong passwords, two-factor tokens or digital certificates notwithstanding, your data in transit is vulnerable, and your network is open to unauthorized access before higher-level authentication takes place.

802.1X provides the framework for challenging access at your network's front door -- the switch or access point -- as well as dynamic key delivery to protect wireless traffic. It's generally a good fit for larger, security-conscious organizations.

While MAC ACLs allow a switch or AP to check MAC addresses before allowing traffic to pass, there's no provision for individual station or user authentication. MAC addresses can be sniffed off wired or wireless transmissions, and the address can then be applied to any NIC that supports configurable MAC addresses.

So, 802.1X may be your best bet to enhance enterprise-level security for both wired and wireless LANs. If your environment already has the basic components for 802.1X support in place, such as 802.1X-compliant APs and switches, and a user base with built-in client software (e.g., Windows XP), deployment can be quick and cost effective.

But it's not for everyone. With added security comes added complexity. 802.1X deployment can be expensive, and vendor support is still far from universal. SOHO networks and companies with older equipment and limited or no wireless deployment may conclude it's simply too costly and complicated. In that case, you may be better served by sticking to MAC ACLs and using encryption for sensitive data.

  • Read more about the X Factor.


    For more information on this topic, visit these resources:

    Rate this Tip
    To rate tips, you must be a member of SearchSecurity.com.
    Register now to start rating these tips. Log in if you are already a member.




    BROWSE BY TAG
    Network Security Tactics,   Infrastructure and Network Security,   Wireless Security Issues,   General Information and Discussion,   VIEW ALL TAGS

    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



    RELATED CONTENT
    Network Security Tactics
    How to prepare for a secure network hardware upgrade
    Preventing SQL injection attacks: A network admin's perspective
    Screencast: How to launch an OpenVAS scan
    Wireless network guidelines for PCI DSS compliance
    Aligning network security with business priorities
    Scanning with N-Stalker offers basic Web application security assessment
    Lifecycle of a network security vulnerability
    Screencast: BackTrack 4 offers an arsenal of penetration testing tools
    Network access control technology: Over-hyped or underused?
    Screencast: Smoothwall offers firewall defense in lean times

    Infrastructure and Network Security
    VPNs: IPsec vs. SSL
    Sensitive student data cracked at U. of Georgia
    Microsoft patches IE spoofing problem
    Geer slams Windows dominance, calls for government intervention
    IE update clears up spoofing issue
    Countdown begins for Mydoom DDoS attacks
    Microsoft to disable spoofing syntax in IE
    IE flaw could fool users in illicit downloads
    Mydoom variant targets security features, Microsoft
    Hackers scanning for ports opened by Mydoom

    Wireless Security Issues
    Adventures in wireless security: Why home and corporate wireless LANs are insecure
    WLAN security tools
    Part 1: Strategies for securing your wireless LAN
    Infosec Know IT All Trivia: Wireless security
    Wireless LAN intrusion detection
    Trend to ponder: Our fragile smart phones
    Slowly but surely, Wi-Fi security is improving
    10 Common questions (and answers) on WLAN security
    Tutorial test: Implementing WLAN security countermeasures
    Defending the WLAN

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary

    DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



  • Research Solutions for Network Security, Access Control and Security Threats
    TechTarget Security Media
    Information Security View this month\\'s issue and subscribe today.
    Information Security Decisions Apply online for free conference admission.
    SearchSecurity.com
    HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Site Map




    All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts