Designing Access Controls
Lay Out the Network
Switch Series | 802.1X | Dynamic VLAN | Dynamic ACLs | ||
|
|
|
| Assignment |
|
|
|
|
|
|
|
3400cl | X | X | X | X |
|
2900 | X | X | X | X |
|
2810 | X | X | X | X |
|
2800 | X | X | X | X |
|
2600 | X | X | X | X |
|
2510 |
|
| X | X |
|
2500 | local only |
| X | X |
|
1800 |
|
|
|
|
|
1700 |
|
|
|
|
|
|
|
|
|
|
|
Public Wireless Zone
The public wireless zone is a wireless environment intended for endpoints, typically laptop computers and PDAs, that belong to guests, customers, or possibly contractors. Often, the goal of the zone is to provide convenient Internet access to people who are not members of your organization. How- ever, you might also grant limited access to private resources: for example, a library could allow access to its catalog.
Table 3-108. Public Wireless Zone Policies
Zone | Authentication | EI Deployment | Testing Method | Authentication | Encryption | ||||
| Method |
|
|
| Protocol |
|
| ||
|
|
|
|
|
|
|
|
|
|
Public wireless | • | • | DHCP | ActiveX | • | PEAP- | • | None | |
| • | 802.1X (high | • | 802.1X |
|
| • | ||
|
| security) |
|
|
| • |
| (higher | |
|
|
|
|
|
|
|
|
| security) |
|
|
|
|
|
|
|
| • | WPA with |
|
|
|
|
|
|
|
|
| 802.1X |
|
|
|
|
|
|
|
|
| (highest |
|
|
|
|
|
|
|
|
| security) |
|
|
|
|
|
|
|
|
|
|
Access Control Method. The public wireless zone may use any of the three access control methods
Although 802.1X is more often associated with private zones, it is possible to use this method for greater security: most wireless client utilities support 802.1X, and you receive the benefit of secure encryption. However, a user may have to alter the settings on his or her