802.1x on g1900 series with multiple client on same port

Options
alexblaise
alexblaise Posts: 4 image  Freshman Member
First Comment Friend Collector

Hello,

i'm trying to set 802.1x security in my company to protect open port, and i've discover a problem.
i have several GS1900 series switches and when only one client is connected on a port with 802.1x autentication it's working well. but if my user connect another micro switch, plug back the autenticated material and another unauticated materail they will be both connected. we also have IP phone with a port for lan and a port for computer. if someone use the computer port they will be connected even if they should'nt.

is there a way to solve that problem?

Thanks

Alex

All Replies

  • PeterUK
    PeterUK Posts: 4,608 image  Guru Member
    250 Answers 2500 Comments Friend Collector Eighth Anniversary
    edited July 28
    Options

    So you tested it?

    I'm sure something about 802.1x security makes it switch port to NIC secure that a switch between makes it not forward the protocol but I guess it could be bypassed.

    unless the Reauthentication Period is 3600 which means it be good for a hour maybe set that lower? don't think it will work

  • alexblaise
    alexblaise Posts: 4 image  Freshman Member
    First Comment Friend Collector
    edited July 29
    Options

    yes i've tried it right before posting this thread.
    i used an IP phone which is set to be authenticate and a laptop not even in my domain. obviously when a plug the laptop on it's own, it's not connected but if i plug it on the PC port of the IP phone after this one got authenticate, the laptop had been connected.

  • Zyxel_Judy
    Zyxel_Judy Posts: 2,626 image  Zyxel Employee
    Zyxel Certified Network Engineer Level 2 - Nebula Zyxel Certified Network Engineer Level 2 - Switch Zyxel Certified Network Engineer Level 2 - Security Zyxel Certified Network Engineer Level 1 - Nebula
    Options

    Hi @alexblaise ,

    What you're seeing is expected behavior on the GS1900 series. This happens because the GS1900 series does not support a configurable host-mode. If the first user enters the correct credential, any other users are allowed to access the port without authentication.

    If strict per-device enforcement is required (e.g., to prevent someone from bypassing 802.1x with a hub/micro switch), you'd need a switch model that supports configurable host-mode, GS1920 series for example and choose "Multi-Secure"

    image.png

    Zyxel_Judy

  • Zyxel_Judy
    Zyxel_Judy Posts: 2,626 image  Zyxel Employee
    Zyxel Certified Network Engineer Level 2 - Nebula Zyxel Certified Network Engineer Level 2 - Switch Zyxel Certified Network Engineer Level 2 - Security Zyxel Certified Network Engineer Level 1 - Nebula
    Options

    Hi @alexblaise ,

    For the GS1900, if you only want to allow a single client to connect to the 802.1x port, you need to combine 802.1x with Port Security and set the Max MAC Entry Number to 1.

    The path to Port Security: Configuration > Security > Port Security > Port

    image.png

    Zyxel_Judy

  • alexblaise
    alexblaise Posts: 4 image  Freshman Member
    First Comment Friend Collector
    edited July 29
    Options

    i was so afraid to get this answer :(

    i have many GS1900 i've paid a lot to have 802.1x on my LAN and it's not enough on those switch.

    thank you for your answer