Network blocking: Difference between revisions

From Security Wiki
Jump to navigationJump to search
No edit summary
 
No edit summary
Line 1: Line 1:
'''Blocking Network Ports'''
'''Blocking Network Ports'''
Jay Dombrowski 2-8-07
Jay Dombrowski 2-8-07




'''1) Objective'''
Brain Storming (no particular order)
MAC Locking
MAC Locking ensures that only specific MAC addresses can access a port, and that traffic from any other MAC addresses will be discarded. You might take advantage of MAC Locking if, for example, you want to prevent more than one user from accessing a port at a given time. There are two kinds of MAC Locking: Dynamic and Static. When you enable Dynamic MAC Locking on a port, the next MAC address that authenticates or accesses  the port (up to the maximum number of dynamic locked MAC addresses allowed) will have exclusive access to that port from that time on. Static MAC Locking lets you create a list of locked MAC addresses for a port so that the port only accepts traffic from those MAC addresses. MAC Locking is only available on devices that support it, and is not allowed on backplane and logical ports.
In order for MAC Locking to take effect on a port, it must be enabled at the device level. You can do this using the Device Configuration wizard, or the device MAC Locking tab. You can enable and disable MAC Locking for a specific port on the Port Properties MAC Locking tab. You can also enable MAC Locking for multiple selected ports in the Port Configuration wizard.
 
-this doc is a policy/standard/guideline
 
-purpose/overview
 
'''2) Scope'''
 
-compulsoryapplies to all hardwired ports on hardware controled by SDSC
 
- or guideline
 
'''3) Document framework'''
 
-status
 
-revision
 
-date reviewed
 
-heading/subheadings
 
'''4) Roles and responsibilities'''


-approval authority
Waht is MAC Locking?


-users
MAC Locking ensures that only specific MAC addresses can access a port, and that traffic from any other MAC addresses will be discarded. You might take advantage of MAC Locking if, for example, you want to prevent more than one user from accessing a port at a given time.


-sec manager
What at the types of port locking?


-managers
There are two kinds of MAC Locking: Dynamic and Static. When you enable '''Dynamic MAC Locking''' on a port, the next MAC address that authenticates or accesses  the port (up to the maximum number of dynamic locked MAC addresses allowed) will have exclusive access to that port from that time on. '''Static MAC Locking''' lets you create a list of locked MAC addresses for a port so that the port only accepts traffic from those MAC addresses. MAC Locking is only available on devices that support it, and is not allowed on backplane and logical ports.


'''5) Goverance'''
How is MAC Locking implemented? 


-implemetation
To take effect on a port, mac port locking must be enabled at the device level. You can do this only by logging onto the switch and executing command line . Perhaps in the future it can be automanted.


-enforcement
What are the results of a violation?


-non-compliance
-users of the port?
-notification?
-How is a violation cleared?
-Restore of service in a timely manor?


-where documents kept
What are the possible configurations? 


-questions
Will we have unique classes of port access?
-office switch?
-one host per port?
-servers?

Revision as of 23:12, 9 February 2007

Blocking Network Ports Jay Dombrowski 2-8-07


Brain Storming (no particular order)

Waht is MAC Locking?

MAC Locking ensures that only specific MAC addresses can access a port, and that traffic from any other MAC addresses will be discarded. You might take advantage of MAC Locking if, for example, you want to prevent more than one user from accessing a port at a given time.

What at the types of port locking?

There are two kinds of MAC Locking: Dynamic and Static. When you enable Dynamic MAC Locking on a port, the next MAC address that authenticates or accesses the port (up to the maximum number of dynamic locked MAC addresses allowed) will have exclusive access to that port from that time on. Static MAC Locking lets you create a list of locked MAC addresses for a port so that the port only accepts traffic from those MAC addresses. MAC Locking is only available on devices that support it, and is not allowed on backplane and logical ports.

How is MAC Locking implemented?

To take effect on a port, mac port locking must be enabled at the device level. You can do this only by logging onto the switch and executing command line . Perhaps in the future it can be automanted.

What are the results of a violation?

-users of the port? -notification? -How is a violation cleared? -Restore of service in a timely manor?

What are the possible configurations?

Will we have unique classes of port access? -office switch? -one host per port? -servers?