Who is really doing 802.1x wired

I am creating a lab environment to test 802.1x prior to implementing it into production.
I wanted to know what is the pros and cons of this security feature at layer 2?
How does it really work behind the scenes?
The reason why i want to implement this feature/function is becuase I'm just one of two network administrators who manage well over 800 networking device (totally cisco shop) and 62 remote sites, and we struggle with the moves, adds, and changes, port vlan assignment (management), users moving there workstations, users moving there voip phones, etc. If anyone can speak on implementing 802.1x wired in a medium to large large network i will be happy to hear about the real life pros and cons

We implemented 802.1x in my previous company (similar size as yours)
You are right it can brings lot of problems.
Before we deployed management solution Cisco LMS 3.0... It really helped us with configuration, config backup, network overview, discrepancy reports, user tracking, troubleshooting (get rid of fake hubs etc..) ... It cleaned our network and saved lot of time .. I suggest to have good management solution before you move to 802.1x
We also separated devices what are not able to authenticate via 802.1x (printers, faxes) to separate VLAN
Than we started in one segment (vlan) which was most stable (no changes, no moves)...
It worked fine.. Than we smoothly moved to other vlans step by step..
The true is that it took lot of time (one of my colleagues was working only on this project for some time).. But we managed it and it works fine.. It would also asked your cisco vendor for consultancy and help
Hope that helps
M.

Similar Messages

  • Does 802.11n give a speed boost on the iPad?

    I did some testing to see if I'd get a speed boost by enabling 802.11n on my Belkin F5D8233-4 router, which supports 802.11n draft specification. I have Verizon FIOS with 25Mbps download/upload. I also have the Verizon router, which only supports 802.11b/g, and I can switch which router I'm connected to in order to compare speeds of 802.11n and 802.11g. All tests were done less than 3 feet from either router.
    Bottom line is that the iPad doesn't get any speed boost by using 802.11n, at least by using speedtest.net to do the testing.
    The test I used was with the speedtest app for the iPhone. I made the Belkin a pure 11n router, and ran that app from the iPad. So the connection had to be 802.11n. Then I connected the iPad to my Verizon router, which had to be 802.11g, and saw virtually no difference.
    I did the same test with a Windows laptop from my job that supports 802.11n. It connected locally to the Belkin router at 72Mbps according to the internal utility. Testing using speedtest.net indicated that using the 802.11n connection on the Belkin was 50% faster than the 802.11g connection on the Verizon router. (About 30Mbps for Belkin/802.11n compared to 20Mbps for Verizon/802.11g for downloads).
    But with the iPad, doing the same test (switching from Belkin router to Verizon router), the speed didn't change. It actually seemed a little slower when I was on 802.11n, but repeated tests showed some variability, and the average was about 19Mbps.
    I realize that the overall speed for the iPad when I'm in my house will get throttled by the FIOS connection max of 25Mbps (although it's interesting that with my MacMini, and the Windows laptop, when connected via 100baseT, I get 30Mbps from FIOS when they promise 25Mbps!). But I can't get the good results from the iPad using 802.11n that I see with the Windows laptop. I'd like to try a local speedtest using the local LAN. I installed Speedtest MINI on the MacMini, enabling the Mac as a server, and the Windows laptop did 72Mbps on the local LAN. But Speedtest MINI requires Flash in the browser, so I can't do that test on the iPad. And the Speedtest app for iPhone doesn't let you pick a local URL for the server.
    So I'm now pretty sure that 802.11n isn't really working right on the iPad with my Belkin router, in terms of delivering increased performance. I've read other posts where people have looked at the transmit rate from the router side, but I really wish I could look at the transmit rate from the iPad (like I do in Mac OS X, or in Windows) to verify.
    To be sure, I'd like to run a speedtest on my local LAN from the iPad. Has anyone been able to actually do some kind of test that verifies the speed of an iPad connection on a local LAN, and does that verification from the iPad, and not the router?
    And finally, has anyone ever done a test that verifies that 802.11n from an iPad delivers a speed boost compared to 802.11g? Are there specific requirements on the router side that need to be satisfied so that the iPad gets a boost? I've read elsewhere where someone said that you only get the boost if using Apple's Airport Extreme as the router (so that you can't really get 802.11n on a non-Apple router), and I think I saw someone say that the router has to support communication over 5.0Ghz for the iPad to be fast on 802.11n. Has Apple ever said what are the real requirements for the iPad to be faster on 802.11n versus 802.11g?

    To the contrary, my experience is that the "G" standard on WiFi provided MUCH faster speeds than the "N" standard on Wi-Fi.  It makes no sense, I know, but it is true.
    I was having horribly slow Wi-Fi speeds on my iPad2, despite a fast cable modem connection and a "N" generation Linksys wireless router (maybe 2-3 yrs old).  Was achieving speeds of only 1.3Mbs -- slow enough that you couldn't watch YouTube videos.  From hunting around on the web, I came across the suggestion to manually set the Wi-Fi router to the "G" standard (ie downgrade it from the faster "N" standard).  Remarkably, I did it and it worked like a charm.  I now get Wi-Fi speeds of about 12 or 13 Mbs, or 10x what I was getting before.  It is an easy fix.  And also I think the "G" standard is capable of 50Mbs so even though it is a slower and older standard, it is still way faster than anything you are likely to achieve as a home user.   I think there is some glitch or oddity in the iPad and iPad2 which can cause it to perform very poorly with older "N" standard WiFi routers.  New ones don't seem to have a problem.

  • Connecting to an 802.1X wired network

    Does the AirPort support connecting to a 802.1X wired network?

    Try turning odd autofill since that sometimes results in entering incorrect information.

  • Windows 7 802.1x (Wired) Authentication Failure when logging into Lync 2010

    Hi
    My company has implemented 802.1x Wired authentication, we use GPO to specify a
    Wired Profile that uses a COMPUTER certificate.
    We are finding that when a Windows 7 laptop comes out of sleep or hibernation, the laptop fails 802.1x authentication and does not connect to the network.
    This issue only occurs intermittently, but have been proven to occur only when Lync 2010 is open.  If we close Lync 2010 the issue does not occur.  Lync 2010 installs a self signed USER certificate for authentication.
    I am aware that there are some issues around Windows 7 not selecting the correct certificate when responding to authentication requests (KB2710995,
    KB2769121) but these always specify that the issue occurs when 802.1x authentication uses USER certificates, not a mix of USER and COMPUTER.  We have installed these hotfixes and the
    issue still occurs.

    Hi,
    From the description, you suspect the DHCP request cause this issue. Would you please send us the packets? Since it seems that you have looked into the traffic and found some clues.
    Meanwhile, I found the following hotfix which may related to this issue.
    No response to 802.1X authentication requests after authentication fails on a computer that is running Windows 7 or Windows Server 2008 R2 http://support.microsoft.com/kb/980295/en-us
    Next Action Plan:
    1.Clean Boot
    a. Click Start, click Run, type "msconfig" (without the quotation marks) in the Open box, and then click OK.
    b. In the Startup tab, click the "Disable All" button.
    c. In the Services tab, check the "Hide All Microsoft Services" checkbox, and then click the "Disable All" button.
    ======================================================
    Clean Boot + binary search
    In a Clean Boot, all the 3rd party services and startup programs are disabled. If the server can start normally in Clean Boot, we can be sure that the issue was caused by some 3rd party service or application. And then we can do a "binary search".
    You can enable half of all the services in Services tab, and then restart the server to check the result. If the issue reoccurs, it means the culprit is in this list; if not, the culprit is in the other half. And then, we can continue the binary search, until
    we find out the root cause. Please let me know if this action plan is OK for you.
    2.Collect etl trace on the problematic client.
    netsh trace start capture=yes overwrite=yes tracefile=c:\net.etl filemode=circular
    ****Try to reproduce this issue****
    netsh trace stop
    Please send the net.etl to us for underlying analysis.
    For any concerns, please let us know.
    Best regards,
    Steven Song
    Please remember to click “Mark as Answer” on the post that helps you, and to click “Unmark as Answer” if a marked post does not actually answer your question. This can be beneficial to other community members reading the thread.

  • 802.1x wired authentication via PEAP, MD5

    Hi everyone,
    Thank you for taking the time for reading this, I am implementing a security solution and wanted to take th benefit of implementing 802.1x over wire. I have been searching a bit but no much info from start to finish on how to implementing this solution,
    i would really appreciate if someone could point me some where  to find  detailed instruction on how to do this, as so far i have been configuring in multiple way bit no result out of it. Still a orange port color on my switch, that means the first
    hop of security work but the next no.
    Thank you in advance to read this.

    Hi,
    According to your description, my understanding is that you want to deploy 802.1x wired authentication via PEAP, MD5 and need instructions about this.
    Some articles and just for your reference:
    802.1X Authenticated Wired Access Overview
    https://technet.microsoft.com/en-us/library/hh831831.aspx
    802.1X Authenticated Wired Access Design Guide
    https://technet.microsoft.com/library/dd378864(WS.10).aspx
    IEEE 802.1X Wired Authentication
    https://technet.microsoft.com/en-us/magazine/2008.02.cableguy.aspx
    Best Regards,
    Eve Wang
    Please remember to mark the replies as answers if they help and unmark them if they provide no help. If you have feedback for TechNet Support, contact [email protected]

  • Solution who encounter 'Setup does not detect Sound Blaster .....' error msg during installat

    For those who encounter 'Setup does not detect sound blaster audio in the system' error upon installing from the installation CD. You can try the steps below that work for me. It seems Windows have lock on to the sound card with an incorrect ID thus the installation CD are not able to correctly identify the card. Be sure to do a backup copy of the registry first incase something goes wrong since we are editing the registry.
    . Go to Start-Run and type in 'regedit' to start the registry editor application.
    2. Go to HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\P CI.
    3. You should see listing with 'VEN....'. Expand them by clicking on the + icon and then see if it's listed as unknown or Creative related stuff. Keep note of them.
    4. Right click on those 'VEN......' listing that you have noted earlier and select full permission. Ensure that full control are selected. Now delete all those listed as unknown or Creative related stuff.
    5. Exit registry editor and reboot. Try using the installation CD again.
    Hope it hel
    ps.
    Message Edited by BadBoy on 05-22-2005 09:5 PM

    I only have this problem when i try to install <A href="]Li'veDrvUni-Pack(ENG).exe[/url] ... That driver pack also says that the drivers from cd are the newest ... :S !

  • Ipad takes photo every time I close the cover of its case. When I close the cover - it really does take a picture and saves a photo. Luckly, it make a click, and pictures are seen in the photo album, and it does not appear to be forwarding.

    When I close the cover - it really does take a picture and saves a photo. Luckly, it make a click, and pictures are seen in the photo album, and it does not appear to be forwarding. It is just gobbling memory and annoying as I can only delete these pictures one at a time.

    It seems to take a picture of the counter top = I do not see the keyboard.
    I am wondering ....It may be a kids game app that takes pictures of the screen or out the back camera. I am starting to think it may just be a sound effect when placing the iPad on its screen. So many things that may be unrelated but coincedental. It started in May (the sound) and so did the multiple pictures - starting to think they are not related.
    Thanks for the quick tip on deleting multiple pictures.

  • IAS and CTA 802.1x wired client?

    Hi,
    We have IAS working with 802.1X authentication. All is good except when we enable dynamic VLAN assignment we come across the Winlogon issue as per MS KB article 935638.
    We do however have available the CTA 802.1X wired client. From what I have read though it requires ACS due to use of EAP-FAST. Is this correct or is there some way I can get CTA 802.1X wired client working with MS IAS RADIUS?
    Thank you

    You will have to use ACS for authenticating using EAP-FAST for CTA 802.1x wired clients. It is not possible to get CTA 802.1X wired client working with MS IAS RADIUS.

  • I am trying to Download the free Maverick 10.9.1 and it's sitting there showing "downloading" but nothing indicates for the last 15 minutes that it is really doing it? Anyone out there has ideas to hare?

    I am trying to Download the free Maverick 10.9.1 and it's sitting there showing "downloading" but nothing indicates for the last 15 minutes that it is really doing it? Anyone out there has ideas to share?

    When I downloaded it, it appeared as if nothing was happening but it actually was being downloaded! It took quite some time to download. I suspect the internet speed affects how quickly it moves.

  • While looking to upgrade to a new MBP, found out latest version of iTunes does not support wired syncing of iCal and contacts. syncing of these must be done through iCloud. This is a deal breaker for me. are there any workarounds?

    While looking to upgrade to a newer MBP, found out latest version of iTunes does not support wired syncing of iCal and contacts. Syncing of these must be done through iCloud. This is a deal breaker for me for several reasons. Are there any workarounds or do I have to go back to a PC with my tail tucked between my legs?

    When you say wired syncing, are you meaning between an iphone and your mac?

  • Systemd with wpa_supplicant 802.1X wired and dhcpcd - Need help

    Hi,
    At work we use 802.1X wired authentication on the network to get access. If successfully authenticated then I get 10.x.x.x network address from DHCP,
    and if not successfully authenticated, I get a 172.x.x.x address from DHCP.
    Now I've configured wpa_supplicant with certificates in its configuration file so that one is working fine.
    What I have problems with is the startup, this is what I need in order:
    * I need wpa_supplicant to start up
    * wpa_supplicant needs to authenticate completely
    * now dhcpcd may run and I should get 10.x.x.x address.
    I've tried two (b*ttfugly) ways of solving this under systemd:
    wpa_auth.service
    [Unit]
    Description=WPA 802.1X
    Requires=sys-subsystem-net-devices-eth0.device
    After=sys-subsystem-net-devices-eth0.device
    [Service]
    Type=simple
    ExecStart=/usr/sbin//wpa_supplicant -ieth0 -Dwired -c/etc/wpa_supplicant/wpa_supplicant.conf
    [Install]
    Alias=multi-user.target.wants/wpa_auth.service
    And in [email protected] I've added:
    After=wpa_auth.service
    However this won't work since wpa_supplicant isn't done authenticating when dhcpcd starts up.
    I've also tried using -B option to wpa_supplicant and forking in wpa_auth.service like this:
    Type=forking
    ExecStart=/usr/sbin//wpa_supplicant -B -ieth0 -Dwired -c/etc/wpa_supplicant/wpa_supplicant.conf
    Now if I'm lucky this works, but it's still a race condition.
    So: Next things I've tried is to make the wpa_auth.service start up a script (Type=forking) that executes wpa_supplicant, and adds a sleep 1, this gives wpa_supplicant 1 second to authenticate, but its still a shitty and unsafe solution.
    Last solution I tried was using the above solution but replaced sleep with wpa_cli -a script that according to man page executes the script when it recieves an event. So right now the chain looks like this:
    In chronological order:
    - wpa_auth.service (systemd)
    Type=forking
    - script
    - wpa_supplicant
    - wpa_cli -a script2 (will block until recieving an CONNECTED/DISCONNECTED event from wpa_supplicant, then run script2)
    - script2
    -pkill wpa_cli
    - exit 0
    done - dhcpcd may start
    I just want to find a way to start dhcpcd after wpa_supplicant has authenticated so I get a correct IP address.
    How do I do this in a correct way? Can I use dbus somehow to make wpa_supplicant signal that it is done authenticating?
    Thanks
    Last edited by dimman (2012-11-23 15:56:01)

    From the sample wpa_supplicant.conf:
    # scan_ssid:
    # 0 = do not scan this SSID with specific Probe Request frames (default)
    # 1 = scan with SSID-specific Probe Request frames (this can be used to
    # find APs that do not accept broadcast SSID or use multiple SSIDs;
    # this will add latency to scanning, so enable this only when needed)
    So... looks like that likely isn't the solution. Of course, this is all just speculation now, until I can resolve the hardware issues or get a new laptop.

  • What is Lingo handler QuickTimeVersion() really doing?

    Hi,
    I am programming with Lingo (vers. 8.5) Macromedia Director files, and use QuickTime VR for the visualisation of 360° panoramas. So QuickTime is needed, but for some of our clients the installation of Apple Quicktime is already a difficulty. Unattended, silent installation as for instance of QuickTime_Alternative.exe of codecguide.com would be much better for them. So I performed some tests.
    After having installed QuickTime_Alternative.exe, I checked with Macromedia Director the version number. The handler " QuickTimeVersion() " gave "8.0100" .
    This is obviously not true. The program QuickTime_Alternative.exe uses the same file and registry values as QuickTime, they state. There is a discussion running on  this subject now on http://codecs.freeforums.org/quicktime-alternative-not-completely-uninstalled-t2387.html
    It would be helpful to know:
    What is >>QuickTimeVersion()<< really doing, when looking after the value?

    Thank you again for your helpful hint. I posted the answer on the forum.
    Sean_Wilson schrieb:
    You seem to be complaining that quicktimeVersion() is giving you the wrong value, but you don't state what you would expect it to return. Maybe you could try Buddy API's baVersion("qt3")
    >

  • Who knows where does IE6 cache jar files?

    who knows where does IE6 cache jar files?
    I don't know why IE6 can't show my new version applet in jar file.I have try to delete all the temporary file by use tools->options->delete temporary files.but it does't work.who can tell me what should i do? thank you,

    Well in that case...I would hope it was cached in the browser...did you look at objects in the cache in (Tools, Internet Options....) in IE?

  • Who knows where does this error message come from

    I have a program wrote with visual age java of ibm.it runs ok in develope page. I exported it in a jar file, it run some minutes and abrrupted with a message like this:
    *** panic: 16-bit string hash table overflow
    abnormal program termination
    who knows where does this error message come from and under which circumstance?

    One thing that comes to mind is that the literal string pool is limited - do you have lots of string literals or itern() lots of strings in your code?

  • Ipod case & scratching - Brasso really does work !!!

    I'm pretty new to this forum and have been reading quite a lot about the scratching of ipod screens. I've been looking for a decent leather case for ages and thought I had found the perfect one of Ebay. After a couple of weeks I removed the ipod from the case and found scratches where the stitching of the case was lying on my black ipod.
    Whilst only minor cosmetic scratches probably wouldn't bother most users I was a little miffed and read up on the use of Brasso - I saw it on this forum and thought that it would never work!
    Well I've tried it today and it really does work, take a lint free cloth, dip one corner in a tiny amount of brasso (you don't need a lot), buff over the scratches with a light circular motion and allow the 'polish' to fog up the case. Leave it for one two seconds and then polish off with the un-wet bit of the cloth.
    My Ipod now looks brand new - I've also now put one of the Crystal film covers on the front (a little pricey at £9.95) but worth it (if stops more scratches).
    So a big thank-you to whoever first suggested Brasso !!! (in the UK brasso costs around £2.50 in most supermarkets !!)
    PC   Windows XP Pro  

    glad it worked for you cause it diddnt work for me it just made some more really good looking scratches sigh

Maybe you are looking for

  • If BB sends a forgotten password to my device, WHERE can I find it?

    If BB sends a forgotten password to my device, WHERE can I find it?It does NOT got into the message box. Thanks Solved! Go to Solution.

  • How to do an average on time series data?

    I need to generate average hold times for various stock of companies as follows: The data looks like: stock        timestamp (sec)            quantity GOOG          12459.6                    -100        <-- SALE GOOG          12634.0                

  • Music on Console stuck on Getting Playlist after altering files

    Header sums it all. I changed directory of some of music files which was in the playlist and mocp is stuck at "Getting the Playlist..." I edited config to not to start in playlist. I also deleted the playlist.m3u which, funnly starts to get created a

  • Scheduled Planner tasks and control validity

    Use case is outlined below: Local Control A is valid from 1/1/14 to 12/31/14. I'm trying to schedule a planner task with activity 'Test Control Effectiveness' for this local control. The task being scheduled is a recurring task starting from 1/1/15 t

  • I-tunes shuts down after 20 sec running

    after updating recently ( version 11.4.0.18 ) it starts normal connects to the store and then couple of seconds later ist says I-Tunsed does not function any more we are looking for a solution then new little window " The program ist not correctly ex