Skip to main content Pricing Hyperconverged Infrastructure Desktop Virtualization Windows Admin Center System Center Windows Server 2019 Windows Server 2016 Extended Security Updates Windows Server Tech Community Documentation Try Windows Server Microsoft Security Azure Dynamics 365 Microsoft 365 Microsoft Teams Windows 365 Microsoft AI Azure Space Mixed reality Microsoft HoloLens Microsoft Viva Quantum computing Sustainability Education Automotive Financial services Government Healthcare Manufacturing Retail Find a partner Become a partner Partner Network Microsoft Marketplace Software companies Blog Microsoft Advertising Developer Center Documentation Events Licensing Microsoft Learn Microsoft Research View Sitemap

Thanks to Steve Riley for pointing out some of the vulnerabilities about my post with using 802.1x to secure wired networks:  (The whitepaper from this post does address these concerns)

Essentially,  the vulnerability is a weakness in the 802.1x protocol — it authenticates only upon connection establishment and assumes all traffic after authentication is legitimate. So if an attacker had physical access to your network, they could unplug an authenticated machine from the switch port and plug it an an ‘attack’ computer and the authenticated computer into a hub that is then connected back to the switch port. A little IP and MAC spoofing……and bingo. (There is a little more to it than that – but you get the gist)

NET/NET – For the highest level of security when using 802.1x for wired networks – use additional defense in depth strategies…..like IPSec.

You can read the more on this here: https://find.codeghost.online/technet/community/columns/secmgmt/sm0805.mspx or in Steve’s Blog.

– Ward Ralston


							Avatar of Microsoft Windows Server Team

Microsoft Windows Server Team posts

See Microsoft Windows Server Team posts