Re: BRIDGE HELP
Grant Taylor <[email protected]> Fri, 11 Jan 2008 13:11:08 -0600
| Newsgroups | gmane.linux.network.bridge.ebtables.user |
|---|---|
| Organization | Riverview Technologies Inc. |
| Message-ID | <[email protected]> |
On 01/11/08 04:48, Peter Volkov wrote: > But remember that it's always possible to spoof mac address. So if > you do not have enough smart switches with port security which allow > you physically bind one port - one client, you should > authenticate/authorize your users by other means: VPN, pppoe, etc... Something else you may want to look in to, if your switches support it, is 802.1x authentication. This way, only your clients will be able to get on to your network. Yes, VPNs, PPPoE, and the likes will add extra authenticity / control / security to your network. However they add extra over head and processing requirements too. There is also the fact that some of them do not play well with things that require a large MTU. Now if your clients had a Linux box at each location, you could do some interesting things that would provide the authenticity / control / security that you want with out having all the overhead. Grant. . . . ------------------------------------------------------------------------- Check out the new SourceForge.net Marketplace. It's the best place to buy or sell services for just about anything Open Source. http://ad.doubleclick.net/clk;164216239;13503038;w?http://sf.net/marketplace