« Layered Security: Solving the Cube | Main | Our 6th Annual IT Hot Topics Conference! »

802.1X Terminology- Port 'Closed'

Posted on Saturday, May 3, 2008 at 07:20PM by Registered CommenterJJ in , | Comments2 Comments

Recently, I’ve been asked to explain my choice of terminology when describing 802.1X during various talks and presentations. One piece of verbiage I tend to use is that an 802.1X-enabled port is ‘shut off’ or ‘closed’ prior to endpoint authentication.

My choice of words seems to raise a few eyebrows with my audience. You, like several others, may ask- “That seems like an ‘untechnical’ term, shouldn’t you say it ‘disables’ the port?” 

Well, no, we shouldn’t say that. When we talk about ‘enable’ and ‘disable’ for ports, that’s actually a port property designation within the switch. When we disable a port in the switch, we’re turning it off and preventing it from passing any traffic.

When we have an 802.1X-enabled port that’s unauthenticated, it still has to pass SOME traffic types, such as EAP (and possibly discovery protocols, such as Cisco’s CDP). Otherwise, we’d never be able to authenticate, right?

So, I, like many others in the NAC world, usually refer to an unauthenticated 1X port as being ‘shut off’ or ‘closed’ just as a means to distinguish it from ‘disabled’ which does have its own meaning.

# # #

EmailEmail Article to Friend

Reader Comments (2)

Perhaps the term "blocked" or "restricted" would be an even better fit :)

May 4, 2008 | Unregistered CommenterNirudha

Nirudha,
Those are some good ideas! Although non-blocking architecture has it's own meaning in switching and routing as well. Restricted might make me feel like it's rate-limited or has ACLs, QoS settings, etc.

jj

May 4, 2008 | Registered CommenterJJ

PostPost a New Comment

Enter your information below to add a new comment.

My response is on my own website »
Author Email (optional):
Author URL (optional):
Post:
 
Some HTML allowed: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <code> <em> <i> <strike> <strong>