Access Control on the Wired Network
LAN Access Switch Topology with IEEE 802.1x Secure Access
Control
Figure 9
Data VLAN 10
Printer
Voice VLAN 11
Data VLAN 10
Securing Access Using 802.1x on a wired LAN
The following tasks are to be performed in the same order that is listed here.
•
•
•
•
•
•
Recommendations for Configuring Security on a Wired LAN
IEEE 802.1x permits or denies network connectivity based on the identity of users and devices. It
provides a link between the user name and IP address, MAC address, and a port on a switch. It also
provides customized network access based on the identity of the end device or user.
The main components of IEEE 802.1x are:
•
•
•
LAN Access Switch Topology with IEEE 802.1x Secure Access Control
Catalyst 3850 stack in access
Switch management
VLAN 100
Desktop user
Recommendations for Configuring Security on a Wired LAN
Provision Common Wired Security Access
Provision in Monitor Mode
Provision in Low-Impact Mode
Provision in High-Impact Mode
Supplicant (end device)
Authenticator (switch)
Authentication server (RADIUS or ISE)
Best Practice User Guide for the Catalyst 3850 and Catalyst 3650 Switch Series
LAN Access Switch Topology with IEEE 802.1x Secure Access Control
Authentication
Server
Data VLAN 10
Desktop user
direct connect
67