Security Basics mailing list archives
Re: MAC level authentication or filtering
From: "Jon Lawhead" <samurai () berkeley edu>
Date: Fri, 08 Oct 2004 11:39:04 -0700
I work for Residential Computing at UC Berkeley, and we use a MAC authentication system in our residence halls with a fairly high rate of success. If you're concerned about MAC spoofing--though it's been our experience here that less than 1% of users have the knowledge and/or motive to bypass the system--consider combining a MAC registration system with a username/password authentication system (i.e. the user would only be able to log on if the username/password matched up with the correct MAC address). I don't have any specific vendor information on this (our system is programmed in-house), but I'm sure it wouldn't be too difficult to either contract out or find something that works.
Jon Lawhead UC Berkeley ResComp On Fri, 8 Oct 2004 12:21:03 +1000 Ajay <abra9823 () mail usyd edu au> wrote:
Quoting David Nardoni <dnardoni () firstresponseconsulting com>:I need a solution that will allow me to prevent a user from coming in to my office and plugging in a laptop and gaining access to the network. I have users that are currently using thin clients to connect to the main server to do all their processing. If a legitimate user turns bad and decides to bring in a system (laptop) from home and connect it to the network and proceed to use their proper username and password to gather information from terminal services, I want to be able to recognize that they have plugged in an unauthorized system and keep them from gaining access to the network. I welcome all ideas no matter what vendor solution or no matter how simple or complex. If you need more info on the situation let me know.i would have said MAC addresses but those can be changed. The person could take the MAC address of the computer that is allowed to connect to the network and which may be switched off and use that. i'm afraid i can't think of anything elseDave Nardoni CISSP First Response Consulting Services, Inc. dnardoni () firstresponseconsulting com---------------------------------------------------------------- This message was sent using IMP, the Internet Messaging Program.
Current thread:
- MAC level authentication or filtering David Nardoni (Oct 07)
- Re: MAC level authentication or filtering Ajay (Oct 08)
- Re: MAC level authentication or filtering Jon Lawhead (Oct 08)
- Re: MAC level authentication or filtering Ajay (Oct 12)
- Re: MAC level authentication or filtering Jon Lawhead (Oct 08)
- RE: MAC level authentication or filtering Kurt (Oct 08)
- RE: MAC level authentication or filtering Jay Archibald (Oct 08)
- Re: MAC level authentication or filtering GuidoZ (Oct 08)
- Re: MAC level authentication or filtering Josh Mills (Oct 08)
- Re: MAC level authentication or filtering Jerry Eblin (Oct 08)
- <Possible follow-ups>
- RE: MAC level authentication or filtering Paris E. Stone (Oct 08)
- Fw: MAC level authentication or filtering GUs (Oct 08)
- RE: MAC level authentication or filtering Roy Sgan-Cohen (Oct 08)
- RE: MAC level authentication or filtering Mike (Oct 08)
(Thread continues...)
- Re: MAC level authentication or filtering Ajay (Oct 08)
