<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: untechnical]]></title>
    <link>http://securityratty.com/tag/untechnical</link>
    <description></description>
    <pubDate>Sat, 03 May 2008 19:20:17 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[802.1X Terminology- Port 'Closed']]></title>
      <link>http://securityratty.com/article/cfb1a2d0be96fd42fe0d83be0faed144</link>
      <guid>http://securityratty.com/article/cfb1a2d0be96fd42fe0d83be0faed144</guid>
      <description><![CDATA[Recently, Ive been asked to explain my choice of terminology when describing 802.1X during various talks and presentations. One piece of verbiage I tend to use is that an 802.1X-enabled port is shut...]]></description>
      <content:encoded><![CDATA[<p>Recently, I&#8217;ve been&nbsp;asked to explain my choice of terminology when describing 802.1X during various talks and presentations. One piece of verbiage I tend to use is that an 802.1X-enabled port is &#8216;shut off&#8217; or &#8216;closed&#8217; prior to endpoint authentication. </p><p>My choice of words seems to raise a few eyebrows with my audience. You, like several others, may ask- &#8220;<em>That seems like an &#8216;untechnical&#8217; term, shouldn&#8217;t you say it&nbsp;&#8216;disables&#8217; the port?&#8221;</em>&nbsp; </p><p>Well, <strong>no,</strong> we shouldn&#8217;t say that. When we talk about &#8216;enable&#8217; and &#8216;disable&#8217; for ports, that&#8217;s actually a port property designation within the switch. When we disable a port in the switch, we&#8217;re turning it off and preventing it from passing any traffic. </p><p>When we have an 802.1X-enabled port that&#8217;s unauthenticated, it still has to pass SOME traffic types, such as EAP (and possibly discovery protocols, such as Cisco&#8217;s CDP). Otherwise, we&#8217;d never be able to authenticate, right?</p><p>So, I, like many others in the NAC world, usually refer to an unauthenticated&nbsp;1X port as being &#8216;shut off&#8217; or &#8216;closed&#8217; just as a means to distinguish it from &#8216;disabled&#8217; which does have its own meaning. </p><p># # #</p>
]]></content:encoded>
      <pubDate>Sat, 03 May 2008 19:20:17 +0000</pubDate>
      <category domain="http://securityratty.com/tag/port">port</category>
      <category domain="http://securityratty.com/tag/port property designation">port property designation</category>
      <category domain="http://securityratty.com/tag/traffic">traffic</category>
      <category domain="http://securityratty.com/tag/possibly discovery protocols">possibly discovery protocols</category>
      <category domain="http://securityratty.com/tag/traffic types">traffic types</category>
      <category domain="http://securityratty.com/tag/ciscos cdp">ciscos cdp</category>
      <category domain="http://securityratty.com/tag/untechnical term">untechnical term</category>
      <category domain="http://securityratty.com/tag/choice">choice</category>
      <category domain="http://securityratty.com/tag/disable">disable</category>
      <source url="http://www.securityuncorked.com/security-uncorked/2008/5/3/8021x-terminology-port-closed.html">802.1X Terminology- Port 'Closed'</source>
    </item>
  </channel>
</rss>
