Friday, March 27, 2020

Network Access Control with non-talkative devices

Hello /r/networking

I was wondering if any of you would have a pro-tip on how to handle the following NAC scenario. For once we are talking about devices that are connected to a switchport that are not noisy. In fact, they do not initiate any communication from their side at all, they just sit and wait until they receive an ARP broadcast that is addressed to them or some server/control device is sending information over to process.

Having such devices together with NAC is, as you can imagine - troublesome. Because the device will not get authenticated if it doesn't initiate network traffic and thus the switch will not be able to create an access-session for this device.

Now my question to you would be: Can you handle such a situation at all if we exclude the option to set the device to DHCP so it shouts once plugged in - let's say the device cannot do DHCP for the sake of the post. If yes, how?

Any brainpower is much appreciated!



No comments:

Post a Comment