Implementing and Operating Cisco Enterprise Network Core Technologies (ENCOR) v1.2InfrastructureMedium
A network engineer is configuring a new Catalyst 9300 switch. The requirement is to ensure that only authenticated devices can access the network through specific access ports. Which security feature should be configured to meet this requirement, allowing the switch to dynamically learn and secure MAC addresses based on authentication?
- ADHCP Snooping
- B802.1X Authentication
- CPort Security
- DIP Source Guard
Show answer & explanationAnswer & explanation
Correct answer: B. 802.1X Authentication
802.1X authentication is the standard for port-based network access control. It requires devices to authenticate with an authentication server (e.g., RADIUS) before gaining network access, thereby securing the access ports from unauthorized devices.
Why the other options are wrong
- A. DHCP Snooping prevents rogue DHCP servers and ensures valid IP address assignments, but doesn't authenticate devices.
- C. Port Security limits the number of MAC addresses on a port and can statically secure MACs, but doesn't provide dynamic authentication based on user/device credentials.
- D. IP Source Guard prevents IP and MAC address spoofing, but relies on other mechanisms for initial device authentication.
802.1X Authentication
A port-based network access control protocol that restricts unauthorized workstations from connecting to a LAN through publicly accessible switch ports.
- Uses a supplicant (client), authenticator (switch), and authentication server (e.g., RADIUS).
- Requires devices to authenticate before gaining network access.
- Can use various authentication methods like EAP (Extensible Authentication Protocol).
Memory trick: Access Control: Authenticate Everything at the Door.