Network Authentamication

Locked
Underpants?
Posts: 4755
Joined: Mon Oct 22, 2001 7:00 am

Network Authentamication

Post by Underpants? »

appliances. Anyone up in this motor scooter use 'em and what positives outweigh the ridiculous cost? I'm looking at a Cisco NAC app, atm.
User avatar
Captain
Posts: 20410
Joined: Thu Jan 05, 2006 2:50 am

Post by Captain »

"Authentamication"?
Underpants?
Posts: 4755
Joined: Mon Oct 22, 2001 7:00 am

Post by Underpants? »

that's right, I'm looking for some edumacation. So ante up or fuck off.
Tormentius
Posts: 4108
Joined: Sat Dec 14, 2002 8:00 am

Post by Tormentius »

What exactly are you trying to accomplish with the appliance? IMO if you're using Active Directory you can control network access fairly effectively using the built-in options (IPSec, for example).
Underpants?
Posts: 4755
Joined: Mon Oct 22, 2001 7:00 am

Post by Underpants? »

specifically, torm, my gripes about ALL conventional methods of network authentication are in the mechanisms. Ok for example, ms chap / radius / kerberos / central login server and AD all can control actions, down to the ability to use a printer. However, there's no ideal way in hosting an open wireless lobby (don't ask-it's a brilliant management thing) to prevent DHCP hijacking, password and identity stealing "sniffers," mac address cloning, inside floods or other crap without micromanaging at the switch level. SOOO... this is my alternative.
Tormentius
Posts: 4108
Joined: Sat Dec 14, 2002 8:00 am

Post by Tormentius »

Ah ok, then the Cisco would work very well. I've been asked to do the same thing on a much smaller (and cheaper) scale and the Fortigate line of routers can authenticate all access against AD so you can limit available ports based on group membership or lack thereof. Their product line runs from SOHO right up into enterprise grade routers though so you might want to check 'em out (you'd gain IDS and definitions-based content management at the same time).

http://www.fortinet.com/
Underpants?
Posts: 4755
Joined: Mon Oct 22, 2001 7:00 am

Post by Underpants? »

I've had one of the 60's at a remote site since about 4 days after Riddla's thread :)
Great appliance.
Tormentius
Posts: 4108
Joined: Sat Dec 14, 2002 8:00 am

Post by Tormentius »

I've got 2 wifi 60s on order now and can't wait to get my hands on them.
+JuggerNaut+
Posts: 22175
Joined: Sun Oct 14, 2001 7:00 am

Post by +JuggerNaut+ »

Underpants? wrote:(don't ask-it's a brilliant management thing)
i'm askin'. PM it.
AmIdYfReAk
Posts: 6926
Joined: Thu Feb 10, 2000 8:00 am

Post by AmIdYfReAk »

Tormentius wrote:I've got 2 wifi 60s on order now and can't wait to get my hands on them.
you will enjoy the things... :)

i know i am.
+JuggerNaut+
Posts: 22175
Joined: Sun Oct 14, 2001 7:00 am

Post by +JuggerNaut+ »

+JuggerNaut+ wrote:
Underpants? wrote:(don't ask-it's a brilliant management thing)
i'm askin'. PM it.
thx dude!
Underpants?
Posts: 4755
Joined: Mon Oct 22, 2001 7:00 am

Post by Underpants? »

anytime, jugg
Tormentius
Posts: 4108
Joined: Sat Dec 14, 2002 8:00 am

Post by Tormentius »

riddla wrote:fucking great shit that fortinet stuff :D

stable as all fuck too.
How are they for VPN stability? The two Netgear V318s that are connecting the sites now constantly have connection drops (usually in the middle of a backup transfer :icon8: )
Tormentius
Posts: 4108
Joined: Sat Dec 14, 2002 8:00 am

Post by Tormentius »

+JuggerNaut+ wrote:
Underpants? wrote:(don't ask-it's a brilliant management thing)
i'm askin'. PM it.
Yeah send it this way too. Sounds interesting.
Underpants?
Posts: 4755
Joined: Mon Oct 22, 2001 7:00 am

Post by Underpants? »

fixed it all with a dmz, ftp server, mad scripts and some pinhole trickery. After paying for the secodary UPS, new hardware, and less 3 hours of sleep per night, the same thing was accomplished for about a tenth of the cost. :icon14:
Tormentius
Posts: 4108
Joined: Sat Dec 14, 2002 8:00 am

Post by Tormentius »

Nice one.
+JuggerNaut+
Posts: 22175
Joined: Sun Oct 14, 2001 7:00 am

Post by +JuggerNaut+ »

Underpants? wrote:fixed it all with a dmz, ftp server, mad scripts and some pinhole trickery. After paying for the secodary UPS, new hardware, and less 3 hours of sleep per night, the same thing was accomplished for about a tenth of the cost. :icon14:
XXXcellent!
Locked