Page 1 of 1

Network Authentamication

Posted: Wed Jul 19, 2006 8:06 pm
by Underpants?
appliances. Anyone up in this motor scooter use 'em and what positives outweigh the ridiculous cost? I'm looking at a Cisco NAC app, atm.

Posted: Wed Jul 19, 2006 8:08 pm
by Captain
"Authentamication"?

Posted: Wed Jul 19, 2006 8:22 pm
by Underpants?
that's right, I'm looking for some edumacation. So ante up or fuck off.

Posted: Wed Jul 19, 2006 8:31 pm
by Tormentius
What exactly are you trying to accomplish with the appliance? IMO if you're using Active Directory you can control network access fairly effectively using the built-in options (IPSec, for example).

Posted: Wed Jul 19, 2006 10:30 pm
by Underpants?
specifically, torm, my gripes about ALL conventional methods of network authentication are in the mechanisms. Ok for example, ms chap / radius / kerberos / central login server and AD all can control actions, down to the ability to use a printer. However, there's no ideal way in hosting an open wireless lobby (don't ask-it's a brilliant management thing) to prevent DHCP hijacking, password and identity stealing "sniffers," mac address cloning, inside floods or other crap without micromanaging at the switch level. SOOO... this is my alternative.

Posted: Wed Jul 19, 2006 10:36 pm
by Tormentius
Ah ok, then the Cisco would work very well. I've been asked to do the same thing on a much smaller (and cheaper) scale and the Fortigate line of routers can authenticate all access against AD so you can limit available ports based on group membership or lack thereof. Their product line runs from SOHO right up into enterprise grade routers though so you might want to check 'em out (you'd gain IDS and definitions-based content management at the same time).

http://www.fortinet.com/

Posted: Wed Jul 19, 2006 10:45 pm
by Underpants?
I've had one of the 60's at a remote site since about 4 days after Riddla's thread :)
Great appliance.

Posted: Wed Jul 19, 2006 10:50 pm
by Tormentius
I've got 2 wifi 60s on order now and can't wait to get my hands on them.

Posted: Thu Jul 20, 2006 12:10 am
by +JuggerNaut+
Underpants? wrote:(don't ask-it's a brilliant management thing)
i'm askin'. PM it.

Posted: Thu Jul 20, 2006 8:14 am
by AmIdYfReAk
Tormentius wrote:I've got 2 wifi 60s on order now and can't wait to get my hands on them.
you will enjoy the things... :)

i know i am.

Posted: Thu Jul 20, 2006 1:36 pm
by +JuggerNaut+
+JuggerNaut+ wrote:
Underpants? wrote:(don't ask-it's a brilliant management thing)
i'm askin'. PM it.
thx dude!

Posted: Thu Jul 20, 2006 1:46 pm
by Underpants?
anytime, jugg

Posted: Thu Jul 20, 2006 6:05 pm
by Tormentius
riddla wrote:fucking great shit that fortinet stuff :D

stable as all fuck too.
How are they for VPN stability? The two Netgear V318s that are connecting the sites now constantly have connection drops (usually in the middle of a backup transfer :icon8: )

Posted: Thu Jul 20, 2006 6:05 pm
by Tormentius
+JuggerNaut+ wrote:
Underpants? wrote:(don't ask-it's a brilliant management thing)
i'm askin'. PM it.
Yeah send it this way too. Sounds interesting.

Posted: Tue Jul 25, 2006 2:59 pm
by Underpants?
fixed it all with a dmz, ftp server, mad scripts and some pinhole trickery. After paying for the secodary UPS, new hardware, and less 3 hours of sleep per night, the same thing was accomplished for about a tenth of the cost. :icon14:

Posted: Tue Jul 25, 2006 5:59 pm
by Tormentius
Nice one.

Posted: Tue Jul 25, 2006 6:04 pm
by +JuggerNaut+
Underpants? wrote:fixed it all with a dmz, ftp server, mad scripts and some pinhole trickery. After paying for the secodary UPS, new hardware, and less 3 hours of sleep per night, the same thing was accomplished for about a tenth of the cost. :icon14:
XXXcellent!