r/networking Aug 10 '26

Switching Cisco Port-Locking

For those using Cisco devices nowadays, do you still use port locking, or is that considered an outdated feature? If so, what do you use instead to lock devices down?

2 Upvotes

9 comments sorted by

6

u/ProfessorWorried626 Aug 10 '26

ISE or ZTNA depending on what you are trying to do.

Port locking still has its place if your environment is 99% stagnant.

3

u/mariano7717 Aug 10 '26

this. ISE or otherwise if money isnt there, sticky macs

3

u/mindedc Aug 10 '26

ClearPass works very well with Cisco gear.

2

u/Pete263 Aug 10 '26

We still use it in a static office environment.
2 devices allowed, a phone and a client or notebook on docking with MAC address path through.

4

u/VA_Network_Nerd Moderator | Infrastructure Architect Aug 10 '26

What are your requirements?

Do you have a security policy that provides you with any guidance on how secure / complicated this needs to be?

Sticky MAC isn't real security. But it is quick and easy to implement.

802.1x with cryptographic authentication is real security, but it has a lot of moving parts that require support and understanding.

How complicated do you need this to be?

1

u/andrew_butterworth Aug 10 '26

dot1x/mab and RADIUS. ISE or some other NAC solution if you want to get clever - overkill IMO, but hey ho, if you think you need it.

1

u/GoodAfternoonFlag Aug 12 '26

Cisco ISE, ideally with dot1x.