Skip to Content

InkBridge Networks - A new name for Network RADIUS

Network access security starts with a yes or a no

Every zero-trust architecture rests on a yes/no admission decision that it assumes is working correctly. 

Alan DeKok, CEO, InkBridge Networks  

The Financial Post ran a feature about me, under the headline "The First Gate of Trust". The idea it landed on, that trust in a network is established at the point of admission before anything else gets a say, is correct, and most people reading a business paper have never thought about it once. 

You have. If you are reading this, you already know what happens at the network edge, and you do not need me to explain RADIUS to you. So rather than repeat the article, I want to say the part I would have said if the audience had been you. 

The decision is binary, and that is not the problem 

A device presents itself, the switch or access point passes the request along, and the server returns one of two answers. In or out. There’s no provisional network, or conditional admission, or "yes, but keep an eye on it." 

This binary decision gets treated as a shortcoming next to the graduated, continuous machinery further up the stack. It is not. A layer that returns one of two answers is a layer you can reason about, and thirty years of production deployment says it returns them reliably. 

The decision is sound. The question is what the gate knows when it makes it. 

Every network has an exception path 

802.1X assumes a supplicant, something on the device able to hold a credential and take part in an exchange. A managed laptop has one. A badge reader does not, and neither does the label printer, the ceiling camera, the HVAC controller, or the several hundred sensors that arrived with a building automation contract. 

So every network of any size has an exception path, and in practice that path is MAC address authentication. The device is admitted because its hardware address is on a list. This is not a secret, nor is it incompetence. It is what you do when a third of your estate cannot authenticate properly and still has to work. 

It is worth being honest about what it costs, though.  

A MAC address is not a credential. It is an identifier, it is visible to anyone on the segment, and it can be changed in software in a few seconds. 

I have written elsewhere about what randomisation did to the assumption that a hardware address identifies anything stable, and the industry is still working through the consequences of that in 802.11bh and in OpenRoaming's move to identity-based credentials. That was a privacy change rather than a security one, and I raise it here only to make a narrow point: the hardware address is having a difficult decade, and a meaningful share of network admission still rests on it. 

Why the exception list only gets longer 

In configuration reviews, the exception list is almost always longer than anyone expected, and a good portion of it cannot be explained by anybody still working there. A MAC range added for a pilot that finished. A fallback VLAN introduced during a migration and described at the time as temporary. 

There is a simple reason for this. A device wrongly kept off the network generates a support ticket within minutes, because somebody cannot work and says so. A device wrongly let on generates nothing at all. No ticket, alert, or complaint. It sits on the correct side of your firewall being trusted by everything you built above it. 

Every operational signal you receive about the admission layer is therefore a complaint about strictness. Nothing ever arrives telling you the gate was too generous. The list grows because only one kind of mistake makes a noise. 

Worth subscribing to.
Worth reading.

Our weekly newsletter covers network authentication tips, how-tos, security vulnerabilities, free resources, standards updates, and industry news. (All stuff you should stay up to date on!)

Thanks for registering!

SIGN UP

Which is why I have been spending time on Accounting 

Of the three parts of the AAA security model, Authentication and Authorisation get the design attention. Accounting is treated as billing data left over from dial-up, or switched off to save disk, or written somewhere nobody has read in years. 

Accounting is the only record of what the gate actually did, rather than what your policy says it should do. That distinction matters a great deal when the failure mode is silent. 

It is part of why I have been involved in the Wireless Broadband Alliance's work on accounting assurance, which now includes a test bed to check whether equipment reports session data correctly. That test exists because you cannot simply assume it does. 

Three questions worth more than a configuration review 

Telling you to review your configuration is not advice, so here is what I would actually want to know about a network I had not seen before. 

  1. What proportion of successful admissions in the last thirty days used MAC address authentication rather than a real credential? Very few people can answer from memory, and the number is usually higher than expected. That figure is your real exposure at the admission layer. 

  2. How many entries on your exception list can you attribute to a person, a reason, and a date? Not how many exist. How many are explicable. The difference between those two numbers is your working queue. 

  3. Can your accounting data answer the first question at all? If getting that number requires a project rather than a query, you have found something more useful than the number. 

The gate is still binary, and it still works. The weak part is the invisible expansion of everything we admit without asking it to prove anything, on a layer nobody is watching. 

Need more help? 

If your team is wrestling with network configuration, a troubleshooting problem you cannot resolve, or a system that needs to be more resilient, we can help. InkBridge Networks has 25 years of expertise - we wrote the standards, maintain FreeRADIUS, and have seen every failure mode there is. Reach out to request a quote.

Related Articles

The RADIUS protocol: How it works and why it's secure

The RADIUS protocol: How it works and why it's secure

Learn how security-by-design improvements have transformed RADIUS into a more secure protocol than the expensive platforms built on top of it. 

AAA information security: building secure network architecture beyond authentication

AAA information security: building secure network architecture beyond authentication

Authentication, Authorisation, and Accounting (AAA) is the security framework that controls who gets onto your network, what they can do once they're there, and what gets logged while they are. 

Is cybersecurity a good career? 30 years in the field
A Q&A with Jana Sedivy for Women in Cyber Day