Techerest

Port Security และ 802.1X บน Cisco Switch คืออะไร? ควบคุมอุปกรณ์และผู้ใช้ใน Network

หลังจากเรียนรู้ DHCP Snooping, Dynamic ARP Inspection และ IP Source Guard แล้ว ขั้นต่อไปของการรักษาความปลอดภัย บริเวณ Access Layer คือการควบคุมว่า อุปกรณ์หรือผู้ใช้ใดสามารถเชื่อมต่อกับ Switch Port ได้

Cisco Switch มีหลายกลไกสำหรับงานนี้ โดยสองแนวคิดสำคัญคือ Port Security และ IEEE 802.1X ซึ่งแม้จะเกี่ยวข้องกับการควบคุม Access Port เหมือนกัน แต่มีหลักการทำงานแตกต่างกัน

Port Security เน้นควบคุม MAC Address ที่อนุญาตบน Switch Port ขณะที่ 802.1X เป็น Port-Based Network Access Control ที่สามารถใช้ Authentication ก่อนอนุญาตให้อุปกรณ์หรือผู้ใช้ เข้าสู่ Network

ภาค 1: Access Layer Security

ทำไมต้องควบคุม Access Port?

ลองพิจารณา Network ในสำนักงาน:

Internet
   |
Firewall
   |
Core / L3 Switch
   |
Access Switch
   |
   +---- PC-A
   |
   +---- PC-B
   |
   +---- Printer
   |
   +---- IP Phone

หาก Switch Port ว่าง และไม่มี Access Control บุคคลที่สามารถเข้าถึง Port ทางกายภาพ อาจนำอุปกรณ์อื่นมาเชื่อมต่อได้

Unused Network Port
        |
        |
        +---- Unknown Device

การกำหนด VLAN เพียงอย่างเดียว ไม่ได้ยืนยันตัวตนว่า ใครเป็นผู้ใช้งาน Port หรืออุปกรณ์ใดควรได้รับอนุญาต

จึงมี Security Controls สำหรับ Access Layer เช่น:

  • Port Security
  • 802.1X
  • DHCP Snooping
  • Dynamic ARP Inspection
  • IP Source Guard
  • ACL
  • VLAN Segmentation

ภาค 2: Cisco Port Security

Port Security คืออะไร?

Switchport Port Security เป็น Feature บน Cisco Switch ที่รองรับสำหรับควบคุม MAC Address ที่ได้รับอนุญาต ให้ใช้งานผ่าน Layer 2 Port

ตัวอย่าง:

PC-A
MAC
AAAA.AAAA.AAAA
       |
       |
    Gi1/0/5
       |
+---------------+
| Cisco Switch  |
| Port Security |
+---------------+

สามารถกำหนด Policy ได้ เช่น:

Gi1/0/5

Maximum MAC = 1

Allowed MAC
AAAA.AAAA.AAAA

หากมี MAC Address เกินกว่าที่ Policy อนุญาต จะเกิด Port Security Violation และ Switch จะตอบสนอง ตาม Violation Mode ที่กำหนด

Maximum MAC Address คืออะไร?

Port Security สามารถจำกัด จำนวน Secure MAC Addresses ที่อนุญาตบน Interface

ตัวอย่าง:

Switch(config)# interface gigabitEthernet 1/0/5
Switch(config-if)# switchport mode access
Switch(config-if)# switchport port-security
Switch(config-if)# switchport port-security maximum 1

หมายความว่า Port นี้ อนุญาต Secure MAC Address ได้สูงสุดหนึ่ง Address ตาม Port Security Configuration

ในบาง Environment เช่น PC เชื่อมต่อผ่าน IP Phone อาจมีมากกว่าหนึ่ง MAC Address บน Physical Port เดียว ดังนั้นค่า Maximum ต้องออกแบบตาม Endpoint Architecture จริง

Secure MAC Address คืออะไร?

Port Security สามารถจัดการ Secure MAC Address ได้หลายรูปแบบ ตาม Platform และ Configuration เช่น:

  • Static Secure MAC
  • Dynamic Secure MAC
  • Sticky Secure MAC

Static Secure MAC

ผู้ดูแลระบบกำหนด MAC Address ที่ได้รับอนุญาตด้วยตนเอง

Switch(config)# interface gigabitEthernet 1/0/5
Switch(config-if)# switchport mode access
Switch(config-if)# switchport port-security
Switch(config-if)# switchport port-security mac-address aaaa.bbbb.cccc

Dynamic Secure MAC

Switch สามารถเรียนรู้ Secure MAC Address แบบ Dynamic ตาม Port Security Behavior ของ Platform

Sticky MAC คืออะไร?

Sticky MAC ช่วยให้ Switch เรียนรู้ MAC Address บน Port และเพิ่ม Sticky Secure MAC เข้าสู่ Running Configuration ตามพฤติกรรมของ Platform

ตัวอย่าง:

Switch(config)# interface gigabitEthernet 1/0/5
Switch(config-if)# switchport mode access
Switch(config-if)# switchport port-security
Switch(config-if)# switchport port-security mac-address sticky

เมื่อ PC ที่ได้รับอนุญาตเชื่อมต่อ:

Gi1/0/5
   |
   +---- PC
         MAC
         AAAA.BBBB.CCCC

Switch สามารถเรียนรู้ Sticky Secure MAC ของ Endpoint ดังกล่าว

หากต้องการให้ Sticky MAC Configuration คงอยู่หลัง Reload ต้องตรวจสอบและบันทึก Configuration ตามขั้นตอน Change Management ของระบบ

Protect, Restrict และ Shutdown ต่างกันอย่างไร?

เมื่อ Port Security พบ MAC Address ที่ละเมิด Policy Cisco Switch สามารถตอบสนอง ตาม Violation Mode

Mode แนวคิด ผลต่อ Port โดยทั่วไป
Protect Drop Traffic จาก MAC ที่ละเมิด Port ยังทำงานสำหรับ Traffic ที่ได้รับอนุญาต
Restrict Drop Traffic ที่ละเมิด พร้อมเพิ่ม Violation Counter และอาจมี Logging/Notification ตาม Platform Port ยังไม่ถูก Shutdown โดย Violation นี้
Shutdown ตอบสนองต่อ Violation โดยทำให้ Port เข้าสู่ Error-Disabled State ตามพฤติกรรมของ Platform Connectivity ของ Port หยุดจนได้รับการ Recovery ที่เหมาะสม

ตัวอย่าง:

Switch(config-if)# switchport port-security violation restrict

หรือ:

Switch(config-if)# switchport port-security violation shutdown
ค่า Default และรายละเอียดของ Violation Behavior ควรตรวจสอบจาก Cisco Documentation สำหรับ Platform และ Software Release ที่ใช้งานจริง

ตัวอย่างตั้งค่า Port Security บน Cisco Switch

สมมติ Gi1/0/5 เป็น Access Port สำหรับ PC หนึ่งเครื่อง:

Switch# configure terminal

Switch(config)# interface gigabitEthernet 1/0/5
Switch(config-if)# switchport mode access
Switch(config-if)# switchport access vlan 10
Switch(config-if)# switchport port-security
Switch(config-if)# switchport port-security maximum 1
Switch(config-if)# switchport port-security mac-address sticky
Switch(config-if)# switchport port-security violation restrict
Switch(config-if)# spanning-tree portfast
Switch(config-if)# exit

ตรวจสอบ:

Switch# show port-security interface gigabitEthernet 1/0/5

ตรวจสอบ Secure MAC:

Switch# show port-security address

ภาค 3: IEEE 802.1X Network Access Control

IEEE 802.1X คืออะไร?

IEEE 802.1X เป็นมาตรฐานสำหรับ Port-Based Network Access Control ที่ใช้ Authentication ก่อนอนุญาต Network Access ตาม Policy

แนวคิด:

User / Device
     |
     | Authentication
     v
Cisco Switch
     |
     v
Authentication Server
     |
     +---- Authorized
     |
     +---- Not Authorized

จุดต่างสำคัญจาก Port Security คือ 802.1X ไม่ได้พิจารณาเพียงว่า MAC Address ใดปรากฏบน Port แต่สามารถใช้ Authentication Framework สำหรับตรวจสอบ Identity หรือ Credential ตามระบบที่องค์กรออกแบบ

Supplicant, Authenticator และ Authentication Server

802.1X มีองค์ประกอบหลักสามบทบาท ที่ควรรู้จัก

องค์ประกอบ ตัวอย่าง หน้าที่
Supplicant PC / Endpoint ขอ Authentication เพื่อเข้า Network
Authenticator Cisco Switch ควบคุม Port และส่งต่อ Authentication Exchange
Authentication Server RADIUS / AAA Server ตรวจสอบ Credential และส่งผล Authentication/Authorization

Topology:

+------------+
| Supplicant |
|    PC      |
+------------+
      |
      | EAPOL
      |
      v
+---------------+
| Authenticator |
| Cisco Switch  |
+---------------+
      |
      | AAA / RADIUS
      |
      v
+----------------------+
| Authentication Server|
| RADIUS / AAA         |
+----------------------+

EAP, EAPOL และ RADIUS เกี่ยวข้องอย่างไร?

ในการเรียน 802.1X ควรแยกคำเหล่านี้ออกจากกัน

EAP

EAP — Extensible Authentication Protocol เป็น Authentication Framework ที่รองรับ Authentication Methods หลายรูปแบบ

EAPOL

EAP over LAN — EAPOL ใช้สำหรับการสื่อสาร 802.1X ระหว่าง Supplicant กับ Authenticator บน LAN

PC
 |
 | EAPOL
 |
 v
Switch

RADIUS

Switch สามารถทำงานร่วมกับ RADIUS Server ในระบบ AAA เพื่อส่งข้อมูล Authentication ไปตรวจสอบที่ Authentication Server

PC
 |
 | EAPOL
 v
Switch
 |
 | RADIUS / AAA
 v
Authentication Server

802.1X Authentication Flow

ลำดับเชิงแนวคิด:

1. Endpoint เชื่อมต่อ Switch Port
             |
             v
2. 802.1X Authentication เริ่มต้น
             |
             v
3. Supplicant / Switch แลกเปลี่ยน EAPOL
             |
             v
4. Switch ส่ง Authentication
   ไปยัง AAA / RADIUS Server
             |
             v
5. Authentication Server
   ตรวจสอบ Credential
             |
        +----+----+
        |         |
        v         v
     Accept     Reject
        |         |
        v         v
   Authorized   Policy / Deny
     Access

หลัง Authentication สำเร็จ ระบบสามารถกำหนด Authorization เพิ่มเติมได้ตาม Architecture เช่น VLAN หรือ Policy บน Platform และ NAC Solution ที่รองรับ

ตัวอย่างแนวคิด 802.1X Configuration บน Cisco Switch

802.1X Configuration แตกต่างกันค่อนข้างมาก ระหว่าง Cisco Platform, IOS/IOS XE Release และ Access Session Architecture

ตัวอย่างต่อไปนี้จึงใช้เพื่ออธิบาย แนวคิด Configuration ไม่ใช่ Template สำหรับ Production

Step 1 — AAA

Switch(config)# aaa new-model

Step 2 — กำหนด RADIUS Server

Syntax ของ RADIUS Configuration แตกต่างตาม Software Release ตัวอย่างรูปแบบหนึ่ง:

Switch(config)# radius server AUTH-SERVER
Switch(config-radius-server)# address ipv4 10.10.10.10 auth-port 1812 acct-port 1813
Switch(config-radius-server)# key YOUR_SHARED_SECRET
Switch(config-radius-server)# exit
อย่าใช้ Shared Secret ตัวอย่าง ในระบบจริง ควรใช้ Secret ที่มีความแข็งแรง และจัดเก็บตาม Security Policy ขององค์กร

Step 3 — AAA Authentication

Switch(config)# aaa authentication dot1x default group radius

Step 4 — เปิด 802.1X System Authentication

บน Cisco IOS/IOS XE บาง Platform อาจใช้:

Switch(config)# dot1x system-auth-control

Step 5 — กำหนด Access Port

ตัวอย่าง Syntax แบบดั้งเดิมที่พบได้บนบาง Platform:

Switch(config)# interface gigabitEthernet 1/0/5
Switch(config-if)# switchport mode access
Switch(config-if)# authentication port-control auto
Switch(config-if)# dot1x pae authenticator
Switch(config-if)# spanning-tree portfast
Switch(config-if)# exit
Cisco IOS XE รุ่นใหม่บาง Platform ใช้ Access Session / Policy Framework และ Syntax อาจแตกต่างจากตัวอย่างข้างต้น จึงต้องตรวจสอบ Configuration Guide ของรุ่นและ Release ที่ใช้งานจริง

ภาค 4: Port Security vs 802.1X

Port Security กับ 802.1X ต่างกันอย่างไร?

หัวข้อ Port Security 802.1X
หลักการ ควบคุม MAC Address บน Port Port-Based Network Access Control
Identity Authentication ไม่ใช่หน้าที่หลัก รองรับผ่าน Authentication Framework
Authentication Server ไม่จำเป็นสำหรับ Port Security พื้นฐาน โดยทั่วไปใช้ AAA/RADIUS Infrastructure
Endpoint Component ไม่ต้องมี 802.1X Supplicant โดยทั่วไปต้องมี Supplicant หรือวิธี Access Control ที่ออกแบบรองรับ
MAC Limit เป็นความสามารถหลัก ไม่ใช่จุดประสงค์หลักของมาตรฐาน
Use Case ควบคุม MAC/จำนวนอุปกรณ์บน Port Authentication และ Network Access Control

จึงไม่ควรมองว่า Port Security และ 802.1X เป็น Feature เดียวกัน

Port Security ตอบคำถามประมาณว่า:

"MAC Address ใด
ได้รับอนุญาตบน Port นี้?"

802.1X ตอบโจทย์ใกล้เคียงกับ:

"Endpoint / User นี้
ผ่าน Authentication
และได้รับอนุญาต
ให้เข้า Network หรือไม่?"

ทำงานร่วมกับ DHCP Snooping, DAI และ IP Source Guard อย่างไร?

เมื่อรวมบทความก่อนหน้า จะเริ่มเห็นภาพของ Access Layer Security ที่สมบูรณ์ขึ้น

                 Endpoint
                    |
                    v
          +-------------------+
          | 802.1X /          |
          | Port Security     |
          +-------------------+
                    |
                    v
          +-------------------+
          | DHCP Snooping     |
          +-------------------+
                    |
                    v
             Binding Database
                    |
             +------+------+
             |             |
             v             v
           DAI           IPSG
             |             |
             v             v
       ARP Validation   Source IP
                        Validation

แต่ละ Feature มีหน้าที่ต่างกัน:

Feature หน้าที่หลัก
Port Security ควบคุม Secure MAC และจำนวน MAC บน Port
802.1X Authentication / Network Access Control
DHCP Snooping ควบคุม DHCP Server Messages และสร้าง Binding
DAI ตรวจสอบ ARP
IP Source Guard ตรวจสอบ Source IP Traffic ที่ Access Port
การนำ Features หลายตัวมาใช้ร่วมกัน ต้องทดสอบ Interaction ระหว่าง Port Security, 802.1X, IP Phone, DHCP Snooping, DAI, IPSG และ Endpoint Behavior ก่อน Deploy ใน Production

ภาค 5: Troubleshooting

Troubleshooting Port Security และ 802.1X

1. ตรวจสอบ Interface Status

Switch# show interfaces status

2. ตรวจสอบ VLAN

Switch# show vlan brief

3. ตรวจสอบ Switchport

Switch# show interfaces gigabitEthernet 1/0/5 switchport

4. ตรวจสอบ Port Security

Switch# show port-security interface gigabitEthernet 1/0/5

ตรวจสอบ:

  • Port Security Enabled หรือไม่
  • Maximum MAC
  • Secure MAC
  • Violation Count
  • Violation Mode

5. ตรวจสอบ Secure MAC

Switch# show port-security address

6. ตรวจสอบ Error-Disabled Port

หากใช้ Shutdown Violation Mode ควรตรวจสอบ Interface Status และ Error-Disable Cause ตามคำสั่งที่ Platform รองรับ

Switch# show interfaces status err-disabled

7. ตรวจสอบ 802.1X Session

คำสั่งแตกต่างตาม Cisco Platform ตัวอย่างที่พบได้ เช่น:

Switch# show authentication sessions

หรือบน Platform/Release บางประเภท:

Switch# show access-session

8. ตรวจสอบ RADIUS

ตรวจสอบว่า Switch สามารถติดต่อ Authentication Server ได้ รวมถึง:

  • IP Reachability
  • Routing
  • UDP Port
  • Shared Secret
  • AAA Configuration
  • RADIUS Policy

9. ตรวจสอบ Client Supplicant

ตรวจสอบว่า Endpoint:

  • เปิดใช้งาน 802.1X
  • ใช้ Authentication Method ถูกต้อง
  • มี Credential/Certificate ตาม Policy
  • เชื่อถือ Certificate Chain ที่เกี่ยวข้อง

10. ตรวจสอบ Log

Switch# show logging

Cisco Lab: Port Security

สำหรับ Lab ขั้นแรก ควรทดลอง Port Security แยกจาก 802.1X ก่อน เพื่อให้เห็นพฤติกรรมของ Secure MAC และ Violation อย่างชัดเจน

Topology

PC-A
 |
 |
Gi1/0/5
 |
+---------------+
| Cisco Switch  |
+---------------+

VLAN 10 USERS

Step 1 — VLAN

Switch(config)# vlan 10
Switch(config-vlan)# name USERS
Switch(config-vlan)# exit

Step 2 — Access Port

Switch(config)# interface gigabitEthernet 1/0/5
Switch(config-if)# switchport mode access
Switch(config-if)# switchport access vlan 10
Switch(config-if)# spanning-tree portfast

Step 3 — Port Security

Switch(config-if)# switchport port-security
Switch(config-if)# switchport port-security maximum 1
Switch(config-if)# switchport port-security mac-address sticky
Switch(config-if)# switchport port-security violation restrict
Switch(config-if)# exit

Step 4 — ตรวจสอบ

Switch# show port-security
Switch# show port-security interface gigabitEthernet 1/0/5
Switch# show port-security address

Step 5 — ทดลองเปลี่ยน Endpoint ใน Lab

หลัง Switch เรียนรู้ Secure MAC ของ PC-A ให้ Disconnect PC-A และเชื่อม PC-B ที่มี MAC Address ต่างกัน ใน Lab Environment

ตรวจสอบอีกครั้ง:

show port-security interface gigabitEthernet 1/0/5
show port-security address
show logging

สังเกต Violation Counter และพฤติกรรมตาม Violation Mode ที่กำหนด

การทดลอง Port Security Violation ควรทำใน Lab ไม่ควรทดลองเปลี่ยน Endpoint บน Production Port ที่ให้บริการระบบสำคัญ

คำสั่ง Cisco ที่ควรรู้

Command หน้าที่
switchport port-security เปิด Port Security
switchport port-security maximum 1 กำหนดจำนวน Secure MAC สูงสุด
switchport port-security mac-address ... กำหนด Static Secure MAC
switchport port-security mac-address sticky เปิด Sticky MAC Learning
switchport port-security violation ... กำหนด Violation Mode
show port-security ตรวจสอบภาพรวม Port Security
show port-security interface ... ตรวจสอบ Port Security ราย Interface
show port-security address ตรวจสอบ Secure MAC Addresses
aaa new-model เปิด AAA Framework
aaa authentication dot1x ... กำหนด 802.1X Authentication Method
dot1x system-auth-control เปิด 802.1X System Authentication บน Platform ที่ใช้ Syntax นี้
show authentication sessions ตรวจสอบ Authentication Sessions บน Platform ที่รองรับ
show access-session ตรวจสอบ Access Sessions บน Platform/Release ที่รองรับ
show logging ตรวจสอบ System Log

คำถามที่พบบ่อย — FAQ

Port Security คืออะไร?

เป็น Feature ที่ช่วยควบคุม Secure MAC Addresses และจำนวน MAC Address ที่อนุญาตให้ใช้งานผ่าน Switch Port

Sticky MAC คืออะไร?

เป็นกลไกที่ช่วยให้ Switch เรียนรู้ MAC Address และสร้าง Sticky Secure MAC ใน Running Configuration ตามความสามารถของ Platform

Port Security Protect, Restrict และ Shutdown ต่างกันอย่างไร?

Protect และ Restrict สามารถ Drop Traffic ที่ละเมิด โดยไม่ Shutdown Port แต่ Restrict มี Violation Counter และอาจมี Notification เพิ่มเติม ส่วน Shutdown Mode สามารถทำให้ Port เข้าสู่ Error-Disabled State เมื่อเกิด Violation ตามพฤติกรรมของ Platform

802.1X คืออะไร?

IEEE 802.1X เป็นมาตรฐาน Port-Based Network Access Control ที่ใช้ Authentication ก่อนอนุญาต Network Access ตาม Policy

Supplicant คืออะไร?

Supplicant คือ Endpoint ที่เข้าร่วมกระบวนการ 802.1X Authentication เช่น PC หรืออุปกรณ์ผู้ใช้งาน

Authenticator คืออะไร?

Authenticator คืออุปกรณ์ ที่ควบคุม Network Access เช่น Cisco Access Switch

Authentication Server คืออะไร?

เป็นระบบที่ตรวจสอบ Authentication Request โดยใน Enterprise Network มักใช้ AAA/RADIUS Infrastructure

802.1X กับ RADIUS เหมือนกันหรือไม่?

ไม่เหมือนกัน 802.1X เป็น Network Access Control Framework ขณะที่ RADIUS เป็น AAA Protocol ที่สามารถใช้ระหว่าง Network Access Device กับ Authentication Server

Port Security ใช้แทน 802.1X ได้หรือไม่?

ไม่ใช่สิ่งเดียวกัน Port Security เน้นควบคุม MAC Address บน Port ขณะที่ 802.1X รองรับ Authentication และ Network Access Control ในระดับที่แตกต่างออกไป

Port Security ป้องกัน MAC Spoofing ได้ทั้งหมดหรือไม่?

ไม่ควรมองว่า MAC Address เป็น Identity ที่พิสูจน์ตัวตนได้อย่างสมบูรณ์ เพราะ MAC Address สามารถถูกเปลี่ยนหรือปลอมได้ Port Security จึงควรเป็นส่วนหนึ่ง ของ Defense in Depth มากกว่าการใช้เป็น Authentication เพียงอย่างเดียว

802.1X ใช้กับ Wi-Fi ได้หรือไม่?

ได้ 802.1X และ EAP ถูกนำมาใช้ใน Enterprise Wireless Security เช่น WPA2-Enterprise และ WPA3-Enterprise ร่วมกับ Authentication Infrastructure ที่เหมาะสม

สรุป

Port Security และ IEEE 802.1X เป็น Security Controls ที่เกี่ยวข้องกับ Access Layer แต่มีวัตถุประสงค์แตกต่างกัน

Port Security ใช้ควบคุม Secure MAC Address จำนวน MAC ที่อนุญาต และกำหนด Violation Action เมื่อพบ MAC Address ที่ไม่สอดคล้องกับ Policy

802.1X เป็น Port-Based Network Access Control ที่ประกอบด้วย Supplicant, Authenticator และ Authentication Server เพื่อทำ Authentication ก่อนอนุญาต Network Access ตาม Policy

เมื่อนำมามองร่วมกับบทความก่อนหน้า เราจะได้ภาพ Access Layer Security:

Endpoint
   |
   v
Port Security / 802.1X
   |
   v
DHCP Snooping
   |
   v
Binding Database
   |
   +----------+
   |          |
   v          v
  DAI        IPSG
   |          |
   v          v
ARP Check   Source IP Check

อย่างไรก็ตาม Security Architecture ที่สมบูรณ์ ยังต้องมี Network Segmentation และ Traffic Policy เพื่อควบคุมว่า หลังจากผู้ใช้ได้รับอนุญาตให้เข้า Network แล้ว สามารถติดต่อ Destination และ Service ใดได้บ้าง

ดังนั้นบทความลำดับต่อไปคือ ACL บน Cisco: Standard ACL, Extended ACL และการควบคุม Traffic ระหว่าง VLAN

Share this
Facebook Share X
TECHEREST COMMUNITY

Share your thoughts here

Join the conversation and share your perspective on this article.

Comments will load when you reach this section.