Hi guys,
I have been doing a bit of research in trying to understand how best to protect access to my network at the ‘access’layer.
I have a complete Cisco environment made up of 2960G’s, 3750’s and Fortigate firewalls. We also have the product LANDesk that has a built in security suite.
At present I am using the ‘port-security’ on all access layer switch ports. This method works great but there is a considerable admin overhead in opening/shutting down ports and maintaining a document of all computers attached to each of the switchports.
I am looking to introduce a centralised control method that using a product (maybe LANDesk) can control who can access the network. I am also looking at a vlan management policy server (think this is the solution) to keep a database of all MAC addresses allowed on the network. I am trying to understand what is the best method.
Does anyone have any whitepapers on this or experience of someething similar?
Thanks
Darren