Skip to content

Comment on RADIUS protocol susceptible to forgery attacks

Comments

RADIUS, LDAP, DIAMETER, sflow, TACAS+, SNMP (all versions), UPS, lights-out management, and similar should never-ever be deployed to public-facing networks. These should remain segregated on internal VLANs used for infrastructure only.

For wireless 802.1x, use clients certs; managed campus APs may still need a tunnel to a RADIUS box, but that's okay.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.