This blog was originally started to better help me understand the technologies in the CCIE R&S blueprint; after completing the R&S track I have decided to transition the blog into a technology blog.
CCIE #29033
This blog will continue to include questions, troubleshooting scenarios, and references to existing and new technologies but will grow to include a variety of different platforms and technologies. Currently I have created over 185 questions/answers in regards to the CCIE R&S track!! Note: answers are in the comment field or within "Read More" section.
Supplicant is responsible for initiating on authenication sessions with the authenticator
Supplicant software can be included in the operating system or you can install a third party supplicant
Role of 802.1x Authenticator
The authenticator is refered to as the NAD (Network Access Device) such as a switch, WLAN controller, firewall, etc..
The supplicant is challenged by the authenicator, the supplicant enters credentials and the NAD passes credentitals to the authentication server. The authenticator also enforces policies on each 802.1x port.
Role of the 802.1x Authentication Server
Performs Authentication, Authorization and Accounting
Validates the authentication credentials of the supplicants that are forwarded by the NAD
Policy look-up based on the supplicant idenitiy and group affiliation and passes the policy to the NAD. This can be the for of DACL (Downloadable ACL) or VLAN assignment
An authentication server for Cisco can include Cisco ISE or Cisco ACS
BYOD (Bring Your Own Device) - There are security concerns when allowing employees, customers, and business partners to bring in there own device and plug it into the corporate network. Cisco has consolidated its ACS and NAC platform into a new product called ISE (Identity Services Engine). This new platform centralizes and simplifies the administration and empowers security groups the ability to make automated decisions. Have a look at the video below:
Terry: this one is for you as I am sure this challenge has come up many times.
I’m excited to announce my latest YouTube video, “CCNA with Packet Tracer
Chapter 5 Review Lab – SOLVED!” now available for viewing here: Watch the
Video...
The debates around IP multicast stopped about five to ten years ago AFAICT.
No one wants to deal with it anymore. In theory, IP multicast was a good
idea b...
Defining service availability using the famous X nines (and all the hacks
like “planned downtime doesn’t count”) is pretty useless in a highly
distribute...
Please join us in congratulating the following iPexpert students who have
passed their CCIE lab! This Week’s CCIE Success Stories Lucas
Handybiantoro, CCIE...
It’s official, the CCIE DC has been announced. Here’s the meat of the
announcement: “Cisco announced today that a new expert-level certification
for data c...
A dynamic, innovative, and skilled individual that is passionate about technology providing technical leadership and architectural oversight. I have in depth knowledge in a variety of technologies which provides a holistic overview of the environment and allows for superior solutions. I take business challenges and create IT solutions that are highly available, scalable, and secure. I have the ability to translate business objectives into IT initiatives. I have a continued thirst for knowledge and share that knowledge with colleagues, business partners, and vendors. I make contributions to the IT community participating in seminars, online forums, and actively blogging.