Several barriers have stalled widespread adoption of LAN edge security, some users say. But as features such as access control lists (ACL) and 802.1x become standard in many vendors’ products, some users are starting to turn them on as an added layer of infrastructure security.
While some hurdles exist, deploying intelligent Ethernet gear at the LAN edge is becoming popular as users seek to tap multilayer switching features to boost security and application bandwidth control.
Several barriers have stalled widespread adoption of LAN edge security, some users say. But as features such as access control lists (ACL) and 802.1x become standard in many vendors’ products, some users are starting to turn them on as an added layer of infrastructure security.
Layer 2 Ethernet is the king of LAN access in most businesses and other organizations, but vendors of Layer 2 switches are increasing the intelligence in these boxes with features that let switches look up data in IP address (Layer 3) and TCP/IP layers (Layer 4) of packets. Many Layer 2 switches can manipulate packet flows based on this Layer 2 to Layer 4 data, allowing for greater quality of service, policy networking and security.
Most corporate LAN switch vendors with wiring closet products, such as Alcatel, Allied Telesyn, Avaya, 3Com, Cisco, Dell, Enterasys Networks, Extreme Networks, Foundry Networks, HP and Nortel have included such features in their stackable and modular Ethernet gear.
The penalty box
At Baylor University in Waco, Texas, a combination of hardware and software was put into action to help the school’s small IT department get a better handle on mischief going on among nosy students with networked PCs.
The IT staff found that a few students were making repeated attempts to hack school database servers. Others were downloading excessive amounts of multimedia files, which clogged the LAN pipes and made network access slow.
To remedy this, the school employed Layer 3 and Layer 4 look-up services on its Enterasys LAN switches and created security policies that limit bandwidth and network access for certain mischievous students. The system is called “the penalty box,” says Bob Hartland, director of IT, networks and servers at Baylor.
During Napster’s heyday several years ago, Hartland says the administration let his staff literally pull the plug on students who were running illicit programs or protocols (such as unauthorized Dynamic Host Configuration Protocol servers used in file-sharing services) out of their dorm rooms. However, this did not go over well with some students and parents, because Baylor markets dorm-room Internet links and charges $15,700 a year in tuition.
“Kids are going to do what they’re going to do,” on the network, Hartland says. “Now instead of disconnecting them completely, we’ll put them in the penalty box. Putting them there allows them still to connect from their rooms, but at restricted subset of services.”
This is done with Enterasys Matrix E1 switches deployed at the dorm wiring closets (more than 3,000 ports) and the company’s User Personalized Network (UPN) and Policy Manager software in the network control center.
The E1 switches support Layer 3 and Layer 4 services such as rate limiting and ACLs based on IP address, User Datagram Protocol (UDP) port and media access control (MAC) address. The UPN software taps into these features and lets the IT staff create policies and roles with certain limitations: a full-featured role might include access to all services at 100M bit/sec, while a limited role (restricted visitors to the network or someone relegated to the penalty box) might be blocked from the Internet, with only access to e-mail and university intranet services at a bandwidth rate less than full capacity.
The Matrix E1 gear with support for ACLs, rate limiting and other features costs more than Enterasys’ standard Layer 2 workgroup switches, Hartland says – about 20% more per port. But the management and security benefits pay off.
“One thing is that our network technicians don’t have go out to the dorms anymore at 10 p.m. to fix problems or disconnect ports,” Hartland says.
At Webster University in St. Louis, ACLs also are used to limit student activities by blocking certain address groups from accessing servers and other resources that are restricted from student access.
Cisco Catalyst 3550 and 2950 switches with support for Layer 3 ACLs, filtering and 802.1x authentication were deployed last year on campus for securing the LAN. The intelligent LAN switches have helped the school give its networked students access to more services around campus while keeping important resources – such as servers for the bursars of financial aid offices – accessible only to authorized personnel, according to Benjamin Hockenhull, network coordinator at Webster.
Standards issues
One LAN security feature many users are still lukewarm on is 802.1x. The IT staffs at Webster and Baylor have not gone forward with widespread use of the authentication standard because 802.1x relies on Microsoft Windows XP clients, the only Windows desktop to support the technology.
The IEEE 802.1x protocol is a standard for authenticating clients to network devices, instead of a LAN directory, such as a Microsoft Active Directory, Novell Directory Services or Lightweight Directory Access Protocol servers. Some security experts say this is a more effective method of securing a LAN because clients that fail a directory server authentication attempt can often see and use network resources, such as printers, unsecured shared storage and Internet access.
According to Scott Day, network services manager at Baylor, 802.1x “is something we’ve been looking at really closely, but one thing we’ve bumped into is compatibility.” While some institutions make their students standardize on one kind of laptop or operating system for network connectivity, Baylor has not adopted that policy, Day adds.
“Anyone running Macintosh or Linux would be left out,” Day says. “It’s ironic that so much network equipment supports 802.1x, but so few clients can use it.”
Slow adoption in businesses
Layer 2 to Layer 4 services at the LAN edge might be catching on in academic institutions, but some business networks are acting more slowly to implement the technology. Often, budgets and corporate policies can be the limiting factors.
“We’re well aware of some of the features our LAN switches are capable of,” says Tony Crognale, network technician at Scottsdale Insurance in Arizona. But he adds that his staff has not turned on features such as ACLs and 802.1x on his network of Extreme BlackDiamond switches because the firm’s parent company, Nationwide Insurance, has yet to set guidelines for how such technology should be implemented.
“We aren’t taking a lot of the [LAN security] measures we should be taking, but I could see that happening in the near future,” Crognale says.
He is particularly interested in locking down users by their MAC addresses to prevent “vendors or other visitors” who come into Scottsdale’s offices from accessing the network with laptops. “Basically, it would eliminate the chance of any outside computers getting on our network,” he says.
Crognale says Nationwide recently instituted a companywide IT security department, which he plans to work with to implement such measures.
“I’m certain we’ll be working very soon to put those features into place,” he says.
| |||||||||||||||||||||




