Designing Access Controls
Lay Out the Network
Table
Switch Series | 802.1X | Dynamic VLAN | Dynamic ACLs | ||
|
|
|
| Assignment |
|
|
|
|
|
|
|
5400zl | X | X | X | X | X |
5300xl | X | X | X | X | X |
4200vl | X | X | X | X |
|
4100gl |
|
| X | X |
|
3500yl | X | X | X | X | X |
3400cl | X | X | X | X |
|
2900 | X | X | X | X |
|
2810 | X | X | X | X |
|
2800 | X | X | X | X |
|
2600 | X | X | X | X |
|
2510 |
|
| X | X |
|
2500 | local only |
| X | X |
|
1800 |
|
|
|
|
|
1700 |
|
|
|
|
|
|
|
|
|
|
|
Private Wireless Zone
The private wireless zone is a wireless network designed for delivering employees the resources they need no matter where they are or how they connect to the network. As with the public wireless zone, endpoints are typically laptops and PDAs that connect wirelessly to APs or RPs. The private wireless zone might blanket your entire organization, or it might include corporate meeting rooms in locations that are not often accessible to guest users.
Because this zone enables greater access to resources, it must provide greater security with strong authentication and encryption.
Table 3-115. Private Wireless Zone Policies
Zone | Access Control | EI Deployment | Testing Method | Authentication | Encryption |
| Method |
|
| Protocol |
|
|
|
|
|
|
|
Private wireless | 802.1X | 802.1X | NAC EI agent | PEAP- | WPA/WPA2 |
|
|
|
|
|
|
|
|
|
|
|
|