Port-Based Authentication

Cisco CCNP Switch (300-115): The Complete Course Introduction to securing a Switch
Welcome back, everyone. All right, so you're not doing switch port security, you want to go with port based authentication. You could, okay. A combination of triple A authentication and port security. How about this feature is based on the I triple E 8021 x. Now, this is not the simplest thing to do.

Okay. Ah for the certification is just learning the basics of a port based authentication is because I want you to imagine this before we even get into this. Okay? Imagine a huge network campus wide branches all over the place all over the states, counties, townships, whatever. And you want to secure your switches but you have hundreds and hundreds and hundreds of employees They're constantly traveling back and forth. All right, plugging in their machines, and it could be multiple machines, maybe they don't have the same laptop every day.

They don't get a silencer they get whatever laptop is available, like they who knows. So you can be going in there. And you could do Sticky, sticky. There's a limitation. Okay. Oh, how many?

I think it's 132 MAC addresses. So if you have 600 employees, they're all using maybe two or three different laptops constantly in different locations. That's an issue. So port based authentication, using 8021 X will take care of that. But if you're in a company, that huge, or an organization that's that big, you need to think that they're using Active Directory. So it's really a combination of both.

I only using a RADIUS server AAA authentication, alright, but also looking at The user accounts in Active Directory. So it's this combination of both. But again, I digress. This is something that you would see in the real world, as long as you understand the basic concept of what you're trying to do. The rest are just a matter of where do I go click. That's it.

Okay. But keep that in mind. Open Mind. All right. If the authentication is successful, then the user can access the port normally, and he has access to the network. So before you can even access the port, or the network, you need to get authenticated by the RADIUS server.

All right. So the way you do it, it's like you would do any triple A authentication, you first new triple A new model, we're going to use RADIUS server, then our RADIUS server is going to be 10 111. The key is gonna be big secret, that is your RADIUS server. That's why I put it there. That's not a command that says, you know, the, hey, this is the RADIUS server. Now you can put whatever you want.

Here. I just put a big secret, whatever. Okay. They can do eight Triple A authentication dot one x. I want to stop right here. The i o s that you have on your switch. Make sure, make sure this is why the licensing was a big issue and the new CCNA the Tony dash 145 the features and always make sure that Dhawan x is a feature within your switch that permits you to do this, okay?

Because you can do triple A, or stack x or radius, but will allow you to do dot one x. All right, keep that in mind. The new default group radius, that's normal. That was not normal. Isn't that one x. Okay, then that one x system authentication control.

You see it on global configuration so far right. Now you're going to the interface, which we're doing a range command through the several gigabit ports, I put one through 15 Switch Port Access VLAN 10. So we're assigning these ports to VLAN 10, switch, promote access that should be members, and then not want export control out all set. So let's get a visualization. So what happens is when these clients are plugging in, they're actually sending the requests or Hey, I want to use a network, it's going to first go like it would if using use normal radius or TAC x. All right?

It's going to go to the RADIUS server. Are you a user in the RADIUS server? Yes, I am. What is your password? This is my password. Okay, you're good to go.

You have been authenticated. Go on ahead and use it. That's what it is. That's all it is, is the same exact thing that you would when we did radius previously and other courses, but the big one is this dot one x right here. Okay. there we're using dot one x.

And again, remember I said the beginning. Keep in mind, keep in mind, huge enterprise organization. With hundreds and hundreds and hundreds and hundreds of employees, putting laptops all over the place. You are going to create manually all these users in the RADIUS server know, you want it to talk to Active Directory. So those can populate automatically. And then when they go, domain controllers are synchronized.

Hey, we learned about synchronization right with NTP and all that good stuff. They're synchronized so they know all the usernames and passwords of every user in every branch. So as these employees go from branch to branch or branch because they travel, they don't have an issue. So this is huge port based authentication is something that's realistic. Okay. There's your commands right there.

If you want take it a step further. So you can see in the real world, hey, how can I make this work together with Active Directory to make your life easy, but it goes beyond the scope of the CCNP switch. But, again, that's something you may want to look into. When you go to your interview. You'd be able to ask those questions. Okay, but the simple triple A authentication, that's all it is, all you're doing is just adding a dot one x.

That's it. All right, and put it in the ports or you're using period. And as usual Hey, can I use a network sure you're authenticated. Go ahead. If you're not gonna Qaeda, you're not going anywhere. That is port based authentication.

See in the next

