3 ms·
I know very little about network-layer security, is there a best practice here? Do people try so hard because they do not like it or is there one per vendor typ
by NationOfJoe 9y ago
I know very little about network-layer security, is there a best practice here? Do people try so hard because they do not like it or is there one per vendor type of thing, nothing open and "standard"
Is this problem not actually solved and your just pointing out how depressing that something seemingly so essential is not solved?
- maruhan2 9y agocurious as well. I first understood it as "how could they struggle with something so basic"
- jon-wood 9y agoTypically wired 802.1x is used in an enterprise setting, where devices are under control of the IT staff. In that case provisioning devices with a certificate can be done easily and it all works pretty smoothly. Likewise enterprise settings want to put all users on the same (or a small number of) VLAN(s). Any devices outside of IT’s control, such as employee phones and tablets, will be restricted to a guest network with no access to anything beyond the internet connection. In this case neither is true - they have no control over devices being connected so can’t rely on SSL certs, and they explicitly want to isolate each user on their own VLAN. Given those constraints this is a much harder problem to solve.