skip to content

When is a per-session ACL worth its cost over a shared NAC quarantine VLAN an intruder can join?

level: seniorimportance: should knowfreq 37%

answer

  1. same decision, two enforcement forms
  2. changing subnet means re-addressing
  3. one broadcast domain of failed devices
  4. filters consume finite switch entries
  5. IPv4-only filter on a dual-stack host

basics

~20 s

A per-session filter restricts one port without moving the device, so nothing re-addresses and failed hosts never sit together. It costs finite switch hardware entries; a shared quarantine VLAN is cheaper but pools every failed device in one broadcast domain.

solid answer

~50 s

Both are enforcement forms of the same decision. Moving the port into a quarantine VLAN changes the subnet, so the endpoint's address is now wrong for where it sits: it needs a fresh lease, which means a port bounce or a forced re-authentication — a visible drop — and every quarantined device shares a broadcast domain with every other unhealthy one, including a device whose owner failed the check on purpose. A per-session ACL is returned as an authorization attribute and applied to that port only: same address, same segment, swappable later without re-addressing. Its price is real — filter entries consume finite hardware resources on access switches, support and entry counts vary by platform, and a filter written only for IPv4 leaves a dual-stack host a second unfiltered path. My default is per-session filtering where the access layer supports it, and a VLAN where it does not.

go deeper

for a junior

Know that a failed health check can either move the port into a restricted VLAN or apply a filter to that port, and that both are ways of expressing the same decision.

for a middle

Explain why a VLAN change forces the endpoint to re-address and a filter change does not, and why that single fact shapes how devices enter and leave quarantine.

for a senior

Choose between the two for a real access layer and defend it with the costs: hardware entry limits, mixed switch generations, address-family coverage, and the concentration of unhealthy hosts in one segment.

for a principal

Own the estate-wide consequence: which enforcement form the access-layer refresh must support, and what you accept in the meantime on hardware that cannot do per-session filtering.

## One decision, two ways to enforce it The policy server has decided this device is not healthy. That decision has to become something a switch port does. There are two forms, and interviewers ask this because candidates conflate them. **VLAN reassignment.** The authorization names a different VLAN and the access port is moved into it. Coarse, universally supported, and it gives quarantine its own address space, its own default gateway and potentially its own resolver. **Per-session filtering.** The authorization carries a filter, applied to that one port for that one session. The device stays in the same VLAN with the same address; what changes is what it is permitted to send. ## The re-addressing problem, which is the point everyone misses If you move a host into a different VLAN, its current address belongs to the old subnet. Nothing about the switch's move tells the operating system that. It keeps an address that is now unroutable where it sits until its lease expires, and it will not usually re-request one because, from the host's point of view, the link never went down. So VLAN-based quarantine needs a forcing function: a port bounce, or a re-authentication that the host treats as a link event. Both are visible — a dropped connection, a re-launch of anything stateful. The same problem appears again, mirrored, on the way out: leaving quarantine is another VLAN change and another bounce. A per-session filter has none of this. Swapping the filter changes what the port permits with no address change and no link event, which is why it is the form that makes graceful movement in and out of quarantine possible. ## What a shared quarantine VLAN concentrates A quarantine VLAN is a broadcast domain whose entire population failed a health check. Some failed because a patch cycle slipped. One may have failed because its owner stopped the health agent deliberately to get placed there. Inside a single segment those devices share a first hop and a layer-2 neighbourhood, and the segment's own reach-list — the routes to patching, identity, DNS and time — is available to all of them equally. Concentrating your unhealthiest machines in one adjacency is an odd thing to do on purpose, and it is the strongest technical argument for per-session filtering: each session gets its own filter, so two quarantined devices are not automatically peers. ## The price of the filter Be honest about it, because this is where the answer separates: - **Hardware resources.** Filter entries are programmed into finite switch hardware tables. A long quarantine filter multiplied by the number of authorized sessions on an access switch can exhaust them, and what happens when it does — entries dropped, sessions failing authorization, or forwarding falling back to software — is a platform property you must know before you deploy, not after. - **Coverage.** Support and maximum entry counts differ across the access layer, and estates rarely have one switch generation. A filter written for IPv4 only, on a dual-stack estate, leaves the host an unfiltered path that the diagram does not show. - **Maintenance.** The reach-list now lives in authorization profiles rather than in one segment's routing and firewall policy, and it must be kept consistent across profiles. Every new remediation destination is edited in more places. - **Direction.** A filter applied to what the port sends restricts what the quarantined device originates. It does not, by itself, stop something else from sending to that device — that depends on the other party's own port having a filter, which a statically configured or unauthenticated port does not. ## How to answer State the mechanism difference first (subnet change versus filter change), then the re-addressing consequence, then the concentration risk of a shared segment, then the cost of the filter in hardware and maintenance. Land on a position: per-session filtering where the access layer supports it and where quarantine needs to be entered and left without disturbing the user; VLAN reassignment on older access hardware, or where quarantine genuinely requires a separate address scope and resolver view — and in that case accept, and say, that entering and leaving both cost a bounce.

  • Why does moving a port into a quarantine VLAN usually require a link bounce?
    The host still holds an address from the old subnet and has no reason to release it: from its side the link never went down. It will keep an unroutable address until the lease expires. A port bounce or a re-authentication the host sees as a link event forces a new lease in the new subnet. A per-session filter avoids this entirely because the address never changes.
  • What happens when quarantine filters exhaust an access switch's hardware entries?
    It is platform-dependent and you must know which behaviour you have before enforcement day: some devices refuse to install the filter and fail the authorization, some drop entries silently, some fall back to slower software handling. All three are outages of a different shape, and the one that fails silently is the dangerous one because the port then permits more than the policy says.
  • A per-session filter restricts what the quarantined device sends. What does that not protect?
    The device itself. A filter on what a port originates does not stop traffic sent toward it, so protection from peers depends on those peers' own ports carrying filters too. A statically configured, unauthenticated or non-participating port has none, which is exactly the kind of device — a printer, a lab box, an appliance — that shares access switches with users.

saying these in an interview costs you the question

  • Thinks a VLAN reassignment takes effect without the endpoint re-addressing
  • Assumes filter entries are free on access switches
  • Ignores that everything in a quarantine VLAN is unhealthy and adjacent
  • Writes an IPv4-only filter for a dual-stack estate
  • Believes a filter on outbound traffic protects the host from its peers
  • Picks one form without naming a single cost of it

context