gumbygaz Posted March 27, 2015 Posted March 27, 2015 We're having issues where 6th form students are bringing in laptops as they're not currently aren't allowed on the Wifi, so they're unplugging PCs and plugging directly into the network and because we've recently added wpad file plugging in gives them internet access.. What do other do to prevent this sort of access. Do others set the DHCP to only issue to registered MAC address table? Any guidance would be great! Thanks Gareth
glen_j Posted March 27, 2015 Posted March 27, 2015 what switches are you using? port security is an option. it wirks on mac addresses so if a user unpluggs a pc to plug their laptop in it either disables the port or ignores the laptop that's plugged in, i know hp and cisco support this not too sure about other brands 1
gumbygaz Posted March 27, 2015 Author Posted March 27, 2015 Yeah we've got HP Procurves, they're managed by the LEA but that sounds exactly what we'd want to implement. I'll fire off an email to them and ask about it. Thanks
TechMonkey Posted March 27, 2015 Posted March 27, 2015 Find in DHCP and add to disallow filter. They won't be able to connect again. Time consuming and they have to have connected once all ready, but worth it if they are repeat offenders. 1
gumbygaz Posted March 27, 2015 Author Posted March 27, 2015 Aye, that I do currently. But as you say, it does mean they have to be on the network already so slight security risk still. hummmm
FN-GM Posted March 27, 2015 Posted March 27, 2015 Setup Radius for these ports in that area. Similar to how its done with WIFI. 1
timbo343 Posted March 27, 2015 Posted March 27, 2015 I thought about getting some of these - RJ45 Port locking clips - not sure how effective they will be in data sockets though. All Products : Cable Management Warehouse, CMW Ltd You could cut the clip off the RJ45 end to prevent the cable being unplugged. 1
free780 Posted March 27, 2015 Posted March 27, 2015 Switch to a configured proxy not wpad its insecure. Implement 802.1x to only allow domain PCs network access. 1
plexer Posted March 27, 2015 Posted March 27, 2015 To be honest however you push out proxy settings it would be possible for someone to gain those details so I wouldn't hang too much on that as an issue. I've used RJ45 locks in the past although they can be broken off. You could look in to a NAC solution such as Counteract, this would effectively control what machines are able to connect and where. Ben
DCUK6 Posted March 28, 2015 Posted March 28, 2015 (edited) Do you allow guests access? If not, What about using DHCP classes. I'm going to try it here to set guests to use a different gateway. Roll out a script to change the class on all of your machines and then change the default classes setting to give out duff settings. Or just check dhcp every so often and ban them. Problem with anything done in dhcp is that can be easily got round with a static IP if they are able to find the details. Edited March 28, 2015 by DCUK6
cpjitservices Posted March 30, 2015 Posted March 30, 2015 Or give them wifi access with captive portal implemented with RADIUS.
FN-GM Posted March 30, 2015 Posted March 30, 2015 Or give them wifi access with captive portal implemented with RADIUS. Not quite as simple as that. SLT might not want it etc. 1
cpjitservices Posted March 30, 2015 Posted March 30, 2015 Not quite as simple as that. SLT might not want it etc. No. But its another option. if SLT would go for it. 1
FN-GM Posted March 30, 2015 Posted March 30, 2015 No. But its another option. if SLT would go for it. It still would mean your ports are vulnerable though 1
gumbygaz Posted March 31, 2015 Author Posted March 31, 2015 Thanks for the tips, couple options. I await the LEA's ideas but was more worried if it was something other schools were doing and we're not but sounds like most already doing the DHCP block option after the event. Have Ruckus for the Wireless and will be doing a captive portal on there for Students. I've suggested the best option would be allow them to use the Wifi (Much like @cpjitservices suggests) so we'd have more control on what devices are on the Network and easily VLanned from the rest of the network. However, FN-GM is right, SLT are the issue with that and Network ports still vulnerable. Any spare ports are unpatched, so perhaps just need to keep better eye on the DHCP logs and get SLT to come down hard on Students abusing it. Thanks for the advice though! 1
DMcCoy Posted March 31, 2015 Posted March 31, 2015 I don't know if it is still in place, but I was using 802.1x for client authentication (and VLAN assignment) along with an unauthenticated VLAN with limited services.
Wubbalubbadub Posted March 31, 2015 Posted March 31, 2015 We don't patch the ports that aren't in use. Leaving them secure. Then for the desktops and printers. we have lockable network cables. Require a key to unlock them. They are fantastic! But expensive!
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now