看板FB_security
标 题RE: Controlling access at the Ethernet level
发信站NCTU CSIE FreeBSD Server (Mon Apr 5 16:04:56 2004)
转信站ptt!FreeBSD.csie.NCTU!not-for-mail
=20
> What would you recommand ? Are there any other elegant solutions ?
>=20
How about using 802.1Q vlan's and dedicate a vlan to each port.
If more than 4000 users then add more gateways.
Just be sure to go for switches that allow you to deny incoming already=20
tagged packets on the user side as some switches passes already tagged =
packets.
For a wireless environment i would suggest PPPoE and VLANs (separating =
them).
> I also heard about 802.1x technology and seems to be an=20
> interesting and professional alternative; I just don't know=20
> how well supported is on the server side, namely FreeBSD.
>=20
802.1x is fairly new and not very well supported yet, expect bugs.
_// Sten Daniel S=F8rsdal
_______________________________________________
[email protected] mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-security
To unsubscribe, send any mail to "
[email protected]"