Skip Links

Network World

Jamey Heary

7 Essential/New features make deploying Wired 802.1x easier on a Cisco infrastructure

By jheary on Sun, 11/23/08 - 11:27pm.

Cisco released a score of new 802.1x features in 12.2.33 SXI for their Catalyst 6500 switch lineup. These new features focus on making dot1x easier to deploy. Hmmm…Is that an oxymoron: dot1x and easy? Well perhaps not anymore. You can now deploy full dot1x features in a quasi “monitor only” mode. This allows you to see what is going to happen in your live environment before you enable true enforcement.

Architecting, implementing, and supporting a wired 802.1x protected network can be one of the most challenging endeavors of your networking career. This is especially true if you find yourself just blindly bumbling through the project and not actively planning and designing for it. I’ve seen my fair share of wired dot1x implementations fail over the years; the reasons vary from customer to customer. But an overarching truth remained constant across them all; “This dot1x stuff is non-trivial!”

In my patch, new 802.1x projects dwindled to almost nothing for a couple years. But recently I’ve seen a strong resurgence by large companies wanting to give it a go or give it another go depending. I’m not going to pretend to know why but if I had to guess I would say it is because 802.1x is riding the recent popularity wave of all things NAC.

So today I wanted to write on the top 7 802.1x switch features you’ll most likely need to pull off a successful deployment. Here they are:

What is Tech Briefcase?
TechBriefcase is a new, free service where IT Professionals can Search, Store and Share IT white papers and content like this. Learn more
Bookmark content
Speed up your research efforts with content across the web.
Search and Store
Find the white papers you need. Create folders for any topic.
View Anywhere
Open your briefcase on your iPhone, tablet or desktop. Share with colleagues.
Don't have an account yet?
About Cisco Security Expert

Jamey Heary, CCIE #7680, sits on the PCI Security Standards Council- Board of Advisors where he provides strategic and technical guidance for future PCI standards. Jamey is the author of Cisco NAC Appliance: Enforcing Host Security with Clean Access. (Check out all of Jamey Heary's books from Cisco Press.) He also has a patent pending on a new DDoS mitigation technique.

Jamey sits on several security advisory boards for Cisco Systems and is a founding member of the Colorado Healthcare InfoSec Users Group. He is an experienced speaker who is recognized as an expert in network security architecture, regulatory compliance, and routing and switching. His other certifications include CISSP, CCSP, and he is a Certified HIPAA Security Professional. He has been working in the IT field for 15 years and in IT security for 10 years. Jamey is currently a Distinguished Systems Engineer at Cisco Systems.

 

Most Discussed Posts