หลังจากเรียนรู้ DHCP Snooping, Dynamic ARP Inspection และ IP Source Guard แล้ว ขั้นต่อไปของการรักษาความปลอดภัย บริเวณ Access Layer คือการควบคุมว่า อุปกรณ์หรือผู้ใช้ใดสามารถเชื่อมต่อกับ Switch Port ได้
Cisco Switch มีหลายกลไกสำหรับงานนี้ โดยสองแนวคิดสำคัญคือ Port Security และ IEEE 802.1X ซึ่งแม้จะเกี่ยวข้องกับการควบคุม Access Port เหมือนกัน แต่มีหลักการทำงานแตกต่างกัน
Port Security เน้นควบคุม MAC Address ที่อนุญาตบน Switch Port ขณะที่ 802.1X เป็น Port-Based Network Access Control ที่สามารถใช้ Authentication ก่อนอนุญาตให้อุปกรณ์หรือผู้ใช้ เข้าสู่ Network
สารบัญ
- ทำไมต้องควบคุม Access Port?
- Port Security คืออะไร?
- Maximum MAC Address
- Secure MAC Address
- Sticky MAC คืออะไร?
- Protect, Restrict และ Shutdown ต่างกันอย่างไร?
- ตั้งค่า Port Security บน Cisco Switch
- IEEE 802.1X คืออะไร?
- Supplicant, Authenticator และ Authentication Server
- EAP และ RADIUS เกี่ยวข้องอย่างไร?
- 802.1X Authentication Flow
- ตัวอย่าง 802.1X บน Cisco Switch
- Port Security กับ 802.1X ต่างกันอย่างไร?
- ทำงานร่วมกับ DHCP Snooping, DAI และ IPSG
- Troubleshooting
- Cisco Lab
- คำสั่ง Cisco ที่ควรรู้
- FAQ
ภาค 1: Access Layer Security
ทำไมต้องควบคุม Access Port?
ลองพิจารณา Network ในสำนักงาน:
Internet
|
Firewall
|
Core / L3 Switch
|
Access Switch
|
+---- PC-A
|
+---- PC-B
|
+---- Printer
|
+---- IP Phone
หาก Switch Port ว่าง และไม่มี Access Control บุคคลที่สามารถเข้าถึง Port ทางกายภาพ อาจนำอุปกรณ์อื่นมาเชื่อมต่อได้
Unused Network Port
|
|
+---- Unknown Device
การกำหนด VLAN เพียงอย่างเดียว ไม่ได้ยืนยันตัวตนว่า ใครเป็นผู้ใช้งาน Port หรืออุปกรณ์ใดควรได้รับอนุญาต
จึงมี Security Controls สำหรับ Access Layer เช่น:
- Port Security
- 802.1X
- DHCP Snooping
- Dynamic ARP Inspection
- IP Source Guard
- ACL
- VLAN Segmentation
ภาค 2: Cisco Port Security
Port Security คืออะไร?
Switchport Port Security เป็น Feature บน Cisco Switch ที่รองรับสำหรับควบคุม MAC Address ที่ได้รับอนุญาต ให้ใช้งานผ่าน Layer 2 Port
ตัวอย่าง:
PC-A
MAC
AAAA.AAAA.AAAA
|
|
Gi1/0/5
|
+---------------+
| Cisco Switch |
| Port Security |
+---------------+
สามารถกำหนด Policy ได้ เช่น:
Gi1/0/5
Maximum MAC = 1
Allowed MAC
AAAA.AAAA.AAAA
หากมี MAC Address เกินกว่าที่ Policy อนุญาต จะเกิด Port Security Violation และ Switch จะตอบสนอง ตาม Violation Mode ที่กำหนด
Maximum MAC Address คืออะไร?
Port Security สามารถจำกัด จำนวน Secure MAC Addresses ที่อนุญาตบน Interface
ตัวอย่าง:
Switch(config)# interface gigabitEthernet 1/0/5
Switch(config-if)# switchport mode access
Switch(config-if)# switchport port-security
Switch(config-if)# switchport port-security maximum 1
หมายความว่า Port นี้ อนุญาต Secure MAC Address ได้สูงสุดหนึ่ง Address ตาม Port Security Configuration
Secure MAC Address คืออะไร?
Port Security สามารถจัดการ Secure MAC Address ได้หลายรูปแบบ ตาม Platform และ Configuration เช่น:
- Static Secure MAC
- Dynamic Secure MAC
- Sticky Secure MAC
Static Secure MAC
ผู้ดูแลระบบกำหนด MAC Address ที่ได้รับอนุญาตด้วยตนเอง
Switch(config)# interface gigabitEthernet 1/0/5
Switch(config-if)# switchport mode access
Switch(config-if)# switchport port-security
Switch(config-if)# switchport port-security mac-address aaaa.bbbb.cccc
Dynamic Secure MAC
Switch สามารถเรียนรู้ Secure MAC Address แบบ Dynamic ตาม Port Security Behavior ของ Platform
Sticky MAC คืออะไร?
Sticky MAC ช่วยให้ Switch เรียนรู้ MAC Address บน Port และเพิ่ม Sticky Secure MAC เข้าสู่ Running Configuration ตามพฤติกรรมของ Platform
ตัวอย่าง:
Switch(config)# interface gigabitEthernet 1/0/5
Switch(config-if)# switchport mode access
Switch(config-if)# switchport port-security
Switch(config-if)# switchport port-security mac-address sticky
เมื่อ PC ที่ได้รับอนุญาตเชื่อมต่อ:
Gi1/0/5
|
+---- PC
MAC
AAAA.BBBB.CCCC
Switch สามารถเรียนรู้ Sticky Secure MAC ของ Endpoint ดังกล่าว
Protect, Restrict และ Shutdown ต่างกันอย่างไร?
เมื่อ Port Security พบ MAC Address ที่ละเมิด Policy Cisco Switch สามารถตอบสนอง ตาม Violation Mode
| Mode | แนวคิด | ผลต่อ Port โดยทั่วไป |
|---|---|---|
| Protect | Drop Traffic จาก MAC ที่ละเมิด | Port ยังทำงานสำหรับ Traffic ที่ได้รับอนุญาต |
| Restrict | Drop Traffic ที่ละเมิด พร้อมเพิ่ม Violation Counter และอาจมี Logging/Notification ตาม Platform | Port ยังไม่ถูก Shutdown โดย Violation นี้ |
| Shutdown | ตอบสนองต่อ Violation โดยทำให้ Port เข้าสู่ Error-Disabled State ตามพฤติกรรมของ Platform | Connectivity ของ Port หยุดจนได้รับการ Recovery ที่เหมาะสม |
ตัวอย่าง:
Switch(config-if)# switchport port-security violation restrict
หรือ:
Switch(config-if)# switchport port-security violation shutdown
ตัวอย่างตั้งค่า Port Security บน Cisco Switch
สมมติ Gi1/0/5 เป็น Access Port สำหรับ PC หนึ่งเครื่อง:
Switch# configure terminal
Switch(config)# interface gigabitEthernet 1/0/5
Switch(config-if)# switchport mode access
Switch(config-if)# switchport access vlan 10
Switch(config-if)# switchport port-security
Switch(config-if)# switchport port-security maximum 1
Switch(config-if)# switchport port-security mac-address sticky
Switch(config-if)# switchport port-security violation restrict
Switch(config-if)# spanning-tree portfast
Switch(config-if)# exit
ตรวจสอบ:
Switch# show port-security interface gigabitEthernet 1/0/5
ตรวจสอบ Secure MAC:
Switch# show port-security address
ภาค 3: IEEE 802.1X Network Access Control
IEEE 802.1X คืออะไร?
IEEE 802.1X เป็นมาตรฐานสำหรับ Port-Based Network Access Control ที่ใช้ Authentication ก่อนอนุญาต Network Access ตาม Policy
แนวคิด:
User / Device
|
| Authentication
v
Cisco Switch
|
v
Authentication Server
|
+---- Authorized
|
+---- Not Authorized
จุดต่างสำคัญจาก Port Security คือ 802.1X ไม่ได้พิจารณาเพียงว่า MAC Address ใดปรากฏบน Port แต่สามารถใช้ Authentication Framework สำหรับตรวจสอบ Identity หรือ Credential ตามระบบที่องค์กรออกแบบ
Supplicant, Authenticator และ Authentication Server
802.1X มีองค์ประกอบหลักสามบทบาท ที่ควรรู้จัก
| องค์ประกอบ | ตัวอย่าง | หน้าที่ |
|---|---|---|
| Supplicant | PC / Endpoint | ขอ Authentication เพื่อเข้า Network |
| Authenticator | Cisco Switch | ควบคุม Port และส่งต่อ Authentication Exchange |
| Authentication Server | RADIUS / AAA Server | ตรวจสอบ Credential และส่งผล Authentication/Authorization |
Topology:
+------------+
| Supplicant |
| PC |
+------------+
|
| EAPOL
|
v
+---------------+
| Authenticator |
| Cisco Switch |
+---------------+
|
| AAA / RADIUS
|
v
+----------------------+
| Authentication Server|
| RADIUS / AAA |
+----------------------+
EAP, EAPOL และ RADIUS เกี่ยวข้องอย่างไร?
ในการเรียน 802.1X ควรแยกคำเหล่านี้ออกจากกัน
EAP
EAP — Extensible Authentication Protocol เป็น Authentication Framework ที่รองรับ Authentication Methods หลายรูปแบบ
EAPOL
EAP over LAN — EAPOL ใช้สำหรับการสื่อสาร 802.1X ระหว่าง Supplicant กับ Authenticator บน LAN
PC
|
| EAPOL
|
v
Switch
RADIUS
Switch สามารถทำงานร่วมกับ RADIUS Server ในระบบ AAA เพื่อส่งข้อมูล Authentication ไปตรวจสอบที่ Authentication Server
PC
|
| EAPOL
v
Switch
|
| RADIUS / AAA
v
Authentication Server
802.1X Authentication Flow
ลำดับเชิงแนวคิด:
1. Endpoint เชื่อมต่อ Switch Port
|
v
2. 802.1X Authentication เริ่มต้น
|
v
3. Supplicant / Switch แลกเปลี่ยน EAPOL
|
v
4. Switch ส่ง Authentication
ไปยัง AAA / RADIUS Server
|
v
5. Authentication Server
ตรวจสอบ Credential
|
+----+----+
| |
v v
Accept Reject
| |
v v
Authorized Policy / Deny
Access
หลัง Authentication สำเร็จ ระบบสามารถกำหนด Authorization เพิ่มเติมได้ตาม Architecture เช่น VLAN หรือ Policy บน Platform และ NAC Solution ที่รองรับ
ตัวอย่างแนวคิด 802.1X Configuration บน Cisco Switch
802.1X Configuration แตกต่างกันค่อนข้างมาก ระหว่าง Cisco Platform, IOS/IOS XE Release และ Access Session Architecture
ตัวอย่างต่อไปนี้จึงใช้เพื่ออธิบาย แนวคิด Configuration ไม่ใช่ Template สำหรับ Production
Step 1 — AAA
Switch(config)# aaa new-model
Step 2 — กำหนด RADIUS Server
Syntax ของ RADIUS Configuration แตกต่างตาม Software Release ตัวอย่างรูปแบบหนึ่ง:
Switch(config)# radius server AUTH-SERVER
Switch(config-radius-server)# address ipv4 10.10.10.10 auth-port 1812 acct-port 1813
Switch(config-radius-server)# key YOUR_SHARED_SECRET
Switch(config-radius-server)# exit
Step 3 — AAA Authentication
Switch(config)# aaa authentication dot1x default group radius
Step 4 — เปิด 802.1X System Authentication
บน Cisco IOS/IOS XE บาง Platform อาจใช้:
Switch(config)# dot1x system-auth-control
Step 5 — กำหนด Access Port
ตัวอย่าง Syntax แบบดั้งเดิมที่พบได้บนบาง Platform:
Switch(config)# interface gigabitEthernet 1/0/5
Switch(config-if)# switchport mode access
Switch(config-if)# authentication port-control auto
Switch(config-if)# dot1x pae authenticator
Switch(config-if)# spanning-tree portfast
Switch(config-if)# exit
ภาค 4: Port Security vs 802.1X
Port Security กับ 802.1X ต่างกันอย่างไร?
| หัวข้อ | Port Security | 802.1X |
|---|---|---|
| หลักการ | ควบคุม MAC Address บน Port | Port-Based Network Access Control |
| Identity Authentication | ไม่ใช่หน้าที่หลัก | รองรับผ่าน Authentication Framework |
| Authentication Server | ไม่จำเป็นสำหรับ Port Security พื้นฐาน | โดยทั่วไปใช้ AAA/RADIUS Infrastructure |
| Endpoint Component | ไม่ต้องมี 802.1X Supplicant | โดยทั่วไปต้องมี Supplicant หรือวิธี Access Control ที่ออกแบบรองรับ |
| MAC Limit | เป็นความสามารถหลัก | ไม่ใช่จุดประสงค์หลักของมาตรฐาน |
| Use Case | ควบคุม MAC/จำนวนอุปกรณ์บน Port | Authentication และ Network Access Control |
จึงไม่ควรมองว่า Port Security และ 802.1X เป็น Feature เดียวกัน
Port Security ตอบคำถามประมาณว่า:
"MAC Address ใด
ได้รับอนุญาตบน Port นี้?"
802.1X ตอบโจทย์ใกล้เคียงกับ:
"Endpoint / User นี้
ผ่าน Authentication
และได้รับอนุญาต
ให้เข้า Network หรือไม่?"
ทำงานร่วมกับ DHCP Snooping, DAI และ IP Source Guard อย่างไร?
เมื่อรวมบทความก่อนหน้า จะเริ่มเห็นภาพของ Access Layer Security ที่สมบูรณ์ขึ้น
Endpoint
|
v
+-------------------+
| 802.1X / |
| Port Security |
+-------------------+
|
v
+-------------------+
| DHCP Snooping |
+-------------------+
|
v
Binding Database
|
+------+------+
| |
v v
DAI IPSG
| |
v v
ARP Validation Source IP
Validation
แต่ละ Feature มีหน้าที่ต่างกัน:
| Feature | หน้าที่หลัก |
|---|---|
| Port Security | ควบคุม Secure MAC และจำนวน MAC บน Port |
| 802.1X | Authentication / Network Access Control |
| DHCP Snooping | ควบคุม DHCP Server Messages และสร้าง Binding |
| DAI | ตรวจสอบ ARP |
| IP Source Guard | ตรวจสอบ Source IP Traffic ที่ Access Port |
ภาค 5: Troubleshooting
Troubleshooting Port Security และ 802.1X
1. ตรวจสอบ Interface Status
Switch# show interfaces status
2. ตรวจสอบ VLAN
Switch# show vlan brief
3. ตรวจสอบ Switchport
Switch# show interfaces gigabitEthernet 1/0/5 switchport
4. ตรวจสอบ Port Security
Switch# show port-security interface gigabitEthernet 1/0/5
ตรวจสอบ:
- Port Security Enabled หรือไม่
- Maximum MAC
- Secure MAC
- Violation Count
- Violation Mode
5. ตรวจสอบ Secure MAC
Switch# show port-security address
6. ตรวจสอบ Error-Disabled Port
หากใช้ Shutdown Violation Mode ควรตรวจสอบ Interface Status และ Error-Disable Cause ตามคำสั่งที่ Platform รองรับ
Switch# show interfaces status err-disabled
7. ตรวจสอบ 802.1X Session
คำสั่งแตกต่างตาม Cisco Platform ตัวอย่างที่พบได้ เช่น:
Switch# show authentication sessions
หรือบน Platform/Release บางประเภท:
Switch# show access-session
8. ตรวจสอบ RADIUS
ตรวจสอบว่า Switch สามารถติดต่อ Authentication Server ได้ รวมถึง:
- IP Reachability
- Routing
- UDP Port
- Shared Secret
- AAA Configuration
- RADIUS Policy
9. ตรวจสอบ Client Supplicant
ตรวจสอบว่า Endpoint:
- เปิดใช้งาน 802.1X
- ใช้ Authentication Method ถูกต้อง
- มี Credential/Certificate ตาม Policy
- เชื่อถือ Certificate Chain ที่เกี่ยวข้อง
10. ตรวจสอบ Log
Switch# show logging
Cisco Lab: Port Security
สำหรับ Lab ขั้นแรก ควรทดลอง Port Security แยกจาก 802.1X ก่อน เพื่อให้เห็นพฤติกรรมของ Secure MAC และ Violation อย่างชัดเจน
Topology
PC-A
|
|
Gi1/0/5
|
+---------------+
| Cisco Switch |
+---------------+
VLAN 10 USERS
Step 1 — VLAN
Switch(config)# vlan 10
Switch(config-vlan)# name USERS
Switch(config-vlan)# exit
Step 2 — Access Port
Switch(config)# interface gigabitEthernet 1/0/5
Switch(config-if)# switchport mode access
Switch(config-if)# switchport access vlan 10
Switch(config-if)# spanning-tree portfast
Step 3 — Port Security
Switch(config-if)# switchport port-security
Switch(config-if)# switchport port-security maximum 1
Switch(config-if)# switchport port-security mac-address sticky
Switch(config-if)# switchport port-security violation restrict
Switch(config-if)# exit
Step 4 — ตรวจสอบ
Switch# show port-security
Switch# show port-security interface gigabitEthernet 1/0/5
Switch# show port-security address
Step 5 — ทดลองเปลี่ยน Endpoint ใน Lab
หลัง Switch เรียนรู้ Secure MAC ของ PC-A ให้ Disconnect PC-A และเชื่อม PC-B ที่มี MAC Address ต่างกัน ใน Lab Environment
ตรวจสอบอีกครั้ง:
show port-security interface gigabitEthernet 1/0/5
show port-security address
show logging
สังเกต Violation Counter และพฤติกรรมตาม Violation Mode ที่กำหนด
คำสั่ง Cisco ที่ควรรู้
| Command | หน้าที่ |
|---|---|
switchport port-security |
เปิด Port Security |
switchport port-security maximum 1 |
กำหนดจำนวน Secure MAC สูงสุด |
switchport port-security mac-address ... |
กำหนด Static Secure MAC |
switchport port-security mac-address sticky |
เปิด Sticky MAC Learning |
switchport port-security violation ... |
กำหนด Violation Mode |
show port-security |
ตรวจสอบภาพรวม Port Security |
show port-security interface ... |
ตรวจสอบ Port Security ราย Interface |
show port-security address |
ตรวจสอบ Secure MAC Addresses |
aaa new-model |
เปิด AAA Framework |
aaa authentication dot1x ... |
กำหนด 802.1X Authentication Method |
dot1x system-auth-control |
เปิด 802.1X System Authentication บน Platform ที่ใช้ Syntax นี้ |
show authentication sessions |
ตรวจสอบ Authentication Sessions บน Platform ที่รองรับ |
show access-session |
ตรวจสอบ Access Sessions บน Platform/Release ที่รองรับ |
show logging |
ตรวจสอบ System Log |
คำถามที่พบบ่อย — FAQ
Port Security คืออะไร?
เป็น Feature ที่ช่วยควบคุม Secure MAC Addresses และจำนวน MAC Address ที่อนุญาตให้ใช้งานผ่าน Switch Port
Sticky MAC คืออะไร?
เป็นกลไกที่ช่วยให้ Switch เรียนรู้ MAC Address และสร้าง Sticky Secure MAC ใน Running Configuration ตามความสามารถของ Platform
Port Security Protect, Restrict และ Shutdown ต่างกันอย่างไร?
Protect และ Restrict สามารถ Drop Traffic ที่ละเมิด โดยไม่ Shutdown Port แต่ Restrict มี Violation Counter และอาจมี Notification เพิ่มเติม ส่วน Shutdown Mode สามารถทำให้ Port เข้าสู่ Error-Disabled State เมื่อเกิด Violation ตามพฤติกรรมของ Platform
802.1X คืออะไร?
IEEE 802.1X เป็นมาตรฐาน Port-Based Network Access Control ที่ใช้ Authentication ก่อนอนุญาต Network Access ตาม Policy
Supplicant คืออะไร?
Supplicant คือ Endpoint ที่เข้าร่วมกระบวนการ 802.1X Authentication เช่น PC หรืออุปกรณ์ผู้ใช้งาน
Authenticator คืออะไร?
Authenticator คืออุปกรณ์ ที่ควบคุม Network Access เช่น Cisco Access Switch
Authentication Server คืออะไร?
เป็นระบบที่ตรวจสอบ Authentication Request โดยใน Enterprise Network มักใช้ AAA/RADIUS Infrastructure
802.1X กับ RADIUS เหมือนกันหรือไม่?
ไม่เหมือนกัน 802.1X เป็น Network Access Control Framework ขณะที่ RADIUS เป็น AAA Protocol ที่สามารถใช้ระหว่าง Network Access Device กับ Authentication Server
Port Security ใช้แทน 802.1X ได้หรือไม่?
ไม่ใช่สิ่งเดียวกัน Port Security เน้นควบคุม MAC Address บน Port ขณะที่ 802.1X รองรับ Authentication และ Network Access Control ในระดับที่แตกต่างออกไป
Port Security ป้องกัน MAC Spoofing ได้ทั้งหมดหรือไม่?
ไม่ควรมองว่า MAC Address เป็น Identity ที่พิสูจน์ตัวตนได้อย่างสมบูรณ์ เพราะ MAC Address สามารถถูกเปลี่ยนหรือปลอมได้ Port Security จึงควรเป็นส่วนหนึ่ง ของ Defense in Depth มากกว่าการใช้เป็น Authentication เพียงอย่างเดียว
802.1X ใช้กับ Wi-Fi ได้หรือไม่?
ได้ 802.1X และ EAP ถูกนำมาใช้ใน Enterprise Wireless Security เช่น WPA2-Enterprise และ WPA3-Enterprise ร่วมกับ Authentication Infrastructure ที่เหมาะสม
สรุป
Port Security และ IEEE 802.1X เป็น Security Controls ที่เกี่ยวข้องกับ Access Layer แต่มีวัตถุประสงค์แตกต่างกัน
Port Security ใช้ควบคุม Secure MAC Address จำนวน MAC ที่อนุญาต และกำหนด Violation Action เมื่อพบ MAC Address ที่ไม่สอดคล้องกับ Policy
802.1X เป็น Port-Based Network Access Control ที่ประกอบด้วย Supplicant, Authenticator และ Authentication Server เพื่อทำ Authentication ก่อนอนุญาต Network Access ตาม Policy
เมื่อนำมามองร่วมกับบทความก่อนหน้า เราจะได้ภาพ Access Layer Security:
Endpoint
|
v
Port Security / 802.1X
|
v
DHCP Snooping
|
v
Binding Database
|
+----------+
| |
v v
DAI IPSG
| |
v v
ARP Check Source IP Check
อย่างไรก็ตาม Security Architecture ที่สมบูรณ์ ยังต้องมี Network Segmentation และ Traffic Policy เพื่อควบคุมว่า หลังจากผู้ใช้ได้รับอนุญาตให้เข้า Network แล้ว สามารถติดต่อ Destination และ Service ใดได้บ้าง
ดังนั้นบทความลำดับต่อไปคือ ACL บน Cisco: Standard ACL, Extended ACL และการควบคุม Traffic ระหว่าง VLAN
Share your thoughts here
Join the conversation and share your perspective on this article.