Hi all,
I'm new to networking and recently started with a new company. I haven't been able to get an answer to this, so I thought I'd try here.
My understanding is that because we use 802.1x and have to configure each AP's IP address on our firewall, when our SOC identifies malware on an endpoint, they can only see the AP's IP address. So if there's, say, 10-20 devices on the AP, there's no way to know exactly which device needs to be remediated.
1. Is this a common implementation? It seems...not great, from a security perspective.
2. Are there any alternatives with our current infrastructure, or would the solution be to move away from 802.1x to something like FortiNAC?
3. Did anything that I just said make any sense, or should I change careers (again)?
I appreciate your time.