Link to home
Start Free TrialLog in
Avatar of credmood
credmood

asked on

Securing your network using MAC Addresses

All, this is a security/switch question so I came to this forum first

I have a problem with people just coming into our offices and plugging there laptops in without asking...:-| Im not best pleased with this but how do I remedy this?

My thoughts are to create a backbone using a layer 3 switch (we have 1 Cisco catalyst switch that we can use) and then create VLANS off of this onto our current switches (this is a seprate idea in that I want to *subnet* certain depts and remote users) ... anyway, my question is can I configure the Cisco switch to accept ONLY certain MAC addreseses? I know I have to build a list of all MAC addresses in the company, however Id rather this than take the chance of someone letting loose a virus just cos we have no *internal* security as such....

Anyone any thoughts on whether this is possible


ASKER CERTIFIED SOLUTION
Avatar of pseudocyber
pseudocyber

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of credmood
credmood

ASKER

Sorry Dr-IP I was a bit flipant with my *no security* statement. I have all the standard security measures in place, virus scans on all machines that update automatically, a software update service that updates MS holes, firewalls that stop the bad people getting in, I also *usually* vet people b4 they plug in, however as we all know you cant be sure with this %100 of the time...., as everyone says its the internal *physical* side of things that has the most flaws. I was just meaning your first line *Setting up something to keep people from being able to just waltz in the door with a laptop and plug it into the network is a good idea security wise* ...

The remote users are always a problem, however I need to a) turn spilt tunneling off and b) set up the cisco vpn client to *kick in* as soon as a connection to the internet is instigated....a problem that Im aware of and need to get round to doing....but as pseudocyber says time and money are not usually on our side ;o)

I'll check out all above, thanks for all your help
All, I will be assigning points to you on this, Im just leaving it open until i get my catalyst switch (this coming week) in which im going to test some points from above
The switch that I got was'nt up to the task, so Im going to have to bet some money from somewhere and buy a decent one....

Thnaks for all your pointers, I will be using them