hi,

I'm just reading the docs of the FastIron and saw there is
MAC based Radius auth. So far so good, but how did u protect from MAC
address forging ? If u have the following situation :

FastIron <---> noname-switch <----> user

In fact I want to achieve a secure way to assign IP address 
to the users and block any attempt from them to forge IP and/or MAC address.


PS. If u point me to solution for the same situation with  Extreme
please tell me it too..
From [EMAIL PROTECTED]  Fri Nov 26 15:33:28 2004
From: [EMAIL PROTECTED] (Niels Bakker)
Date: Fri Nov 26 15:33:35 2004
Subject: [f-nsp] mac address forging !
In-Reply-To: <[EMAIL PROTECTED]>
References: <[EMAIL PROTECTED]>
Message-ID: <[EMAIL PROTECTED]>

* [EMAIL PROTECTED] (iVAN G) [Fri 26 Nov 2004, 15:36 CET]:
> I'm just reading the docs of the FastIron and saw there is
> MAC based Radius auth. So far so good, but how did u protect from MAC
> address forging ? If u have the following situation :
> 
> FastIron <---> noname-switch <----> user

You don't.  You could use port security to keep MACs locked to one
particular port but that doesn't protect users on the noname switch.


> In fact I want to achieve a secure way to assign IP address 
> to the users and block any attempt from them to forge IP and/or MAC address.

use 802.1X


        -- Niels.

-- 
From [EMAIL PROTECTED]  Fri Nov 26 17:58:02 2004
From: [EMAIL PROTECTED] (iVAN G)
Date: Fri Nov 26 17:58:09 2004
Subject: [f-nsp] mac address forging !
In-Reply-To: <[EMAIL PROTECTED]>
References: <[EMAIL PROTECTED]>
        <[EMAIL PROTECTED]>
Message-ID: <[EMAIL PROTECTED]>

Yes I thought about this, but this only protect for authenticating the
correct user once it is
auth the user can modify the IP address with whatever it wants i.e
forge the address.
i.e. it will be able to present himself like different user.
How do u protect from this ?
The only thing I can come up till now is usage of some weird way of
VLANID i.e. set different
VLANID on every port on every noname-switch then I had to have some way to
set IP address via DHCP based on the VLANID.and similar ...along these lines....

I'm wondering how do u ppl do these things. is there some hidden
feature.:") i dont know of.

The thing needed is a way to securely give the user specific IP
address/es via DHCP with
ability to forbid user access if it forges MAC and/or IP address when
u are at mixed
envoirment i.e not only Foundry switches.

sorry if I'm asking too much..


PS. On the CATV I use the following technique.
The DHCP server gives the user IP based on the cable modem MAC address.
The advantages are :
  - modem MAC addresses are almost imposiblle to be forged, even if they
    succeed with some older modems there is other means of blocking them :")
  - I dont have to remember/store users ethernet card MAC addresses
    i.e. they can change it at any time they want w/o botering me, but
    they still get the correct IP. 
  - And if they try to change their IP address their access is blocked 
     on the cable modem.
  - based on their unforged IP i give them the correct services

In my case possibly if foundry switches can change dhcp option-82 on the fly
to include vlanid, ingress-foundry-port, foundry-switch-MAC :") !!! then ...


On Fri, 26 Nov 2004 21:33:28 +0100, Niels Bakker
<[EMAIL PROTECTED]> wrote:
> * [EMAIL PROTECTED] (iVAN G) [Fri 26 Nov 2004, 15:36 CET]:
> > I'm just reading the docs of the FastIron and saw there is
> > MAC based Radius auth. So far so good, but how did u protect from MAC
> > address forging ? If u have the following situation :
> >
> > FastIron <---> noname-switch <----> user
> 
> You don't.  You could use port security to keep MACs locked to one
> particular port but that doesn't protect users on the noname switch.
> 
> 
> > In fact I want to achieve a secure way to assign IP address
> > to the users and block any attempt from them to forge IP and/or MAC address.
> 
> use 802.1X
> 
>         -- Niels.
> 
> --
> _______________________________________________
> foundry-nsp mailing list
> [email protected]
> http://puck.nether.net/mailman/listinfo/foundry-nsp
>
From [EMAIL PROTECTED]  Sat Nov 27 16:09:34 2004
From: [EMAIL PROTECTED] (iVAN G)
Date: Sat Nov 27 16:09:40 2004
Subject: [f-nsp] dhcp relay support
Message-ID: <[EMAIL PROTECTED]>

does foundry switches support dhcp-relay ?
what about option-82 ?
If yes could u show me some CLI example ?

tia
From [EMAIL PROTECTED]  Sun Nov 28 19:51:24 2004
From: [EMAIL PROTECTED] (Niels Bakker)
Date: Sun Nov 28 19:51:31 2004
Subject: [f-nsp] mac address forging !
In-Reply-To: <[EMAIL PROTECTED]>
References: <[EMAIL PROTECTED]>
        <[EMAIL PROTECTED]>
        <[EMAIL PROTECTED]>
Message-ID: <[EMAIL PROTECTED]>

* [EMAIL PROTECTED] (iVAN G) [Sat 27 Nov 2004, 00:00 CET]:
> Yes I thought about this, but this only protect for authenticating the
> correct user once it is auth the user can modify the IP address with
> whatever it wants i.e forge the address.

IP address, not MAC address as you said in the subject of your mails.

IP is one layer above where the switch operates.  Look at the router.
Right now I know of no workable "secure arp" implementation, you'll
probably want to look at IPsec and force all traffic to be properly
encrypted and authenticated.


> i.e. it will be able to present himself like different user.
> How do u protect from this ?

Best of luck securing your end stations against malware designed to
steal your users' certificates


        -- Niels.

-- 
From [EMAIL PROTECTED]  Tue Nov 30 19:53:58 2004
From: [EMAIL PROTECTED] (Gunther Stammwitz)
Date: Tue Nov 30 19:53:41 2004
Subject: [f-nsp] Experiences with the performance of Foundy Bigiron 8000 VS
        a Cisco 12000 & redundancy question
Message-ID: <[EMAIL PROTECTED]>

Hello my dear colleagues,
 
first of all let me say: yes - I know this is a Cisco-only mailing list but
my question is directly connected to Cisco so please give me a chance.
I'm CCing the foundry-nsp list here and hope that my cross post doesn't
disturb anyone but will help to find people who have experience with cisco
as well as foundry gear.

 
We're trying to increase our redundancy and I'm trying to decide whether it
is better to buy a Foundry Bigiron 8000 in addition to our existing Cisco
GSR8/40 or if - maybe - a second Cisco would be the better choice.

At the moment we have a GSR8/40 that is full redundant and utilizes 2 GRPs
with 256 MB ram and we're using GE-GBIC-SC-B line cards and they match our
requirements which are to handle about 200 megabits of traffic AND to
sustain a hard (d)dos-attack which might be up to a gigabit of fragmented
traffic. I'm talking about ipv4 traffic of course which will be routed in
hardware. I know that ipv6 is a software-only thing on our "old" line cards
but for the moment that's okay.
Regarding the current discussion of the growing bgp tables: I know that we
will sooner or later run into problems regarding the memory.. but that's not
the topic right now.
 
In order to increase our redundancy we'd like to install a second router.
My first thought was to buy another GSR 8/40 but this time with a GRP-B that
has 512MB of ram but in connection with the required line card(s) this will
be pretty expensive.
 
A colleague just showed me his Foundry BigIron that was equipped with a
B4GMR4 M4 Management Module that carries 512MB ram and 4 gigabit ports.
[by the way: with 4 full feeds only about 40% of the memory are in use.
Looks like they have a better software than Cisco]
>From the economic perspective the bigiron 8000 is very interesting: costs
only about a third of the Cisco and does even have 4 Gigabit ports!
He told me that the router does "line speed" and can sustain dos-attacks of
more than a gigabit without any problems but that was all he knew. The
datasheets on Foundry's website are more the marketing like stuff.

by the way: the gsr as well as the bigiron can both do VRRP. Will both
implementations work together in one vrrp-installation?
 
==> Does anyone have a real experience with Foundry Bigiron-gear and know
how good/bad it runs compared to Cisco.
 
 
I'm asking myself right now whether to buy another Cisco which is good since
I know how to administer the gear and you can find a external technician
easily. We could also exchange line cards between both routers. A big CON is
that it is exactly the same gear we have right now and if there's an ios
fault most probably both machines will fail.
 
 
What do you think?
First of all: can the foundry handle the load and second: what's the better
solution in order to increase our redundancy?
 
Thanks for your help in advance,
Gunther
 
 
-------------- next part --------------
An HTML attachment was scrubbed...
URL: 
https://puck.nether.net/pipermail/foundry-nsp/attachments/20041201/5bba2388/attachment.html

Reply via email to