Jump to content

Recommended Posts

Posted

We're having issues where 6th form students are bringing in laptops as they're not currently aren't allowed on the Wifi, so they're unplugging PCs and plugging directly into the network and because we've recently added wpad file plugging in gives them internet access..

 

What do other do to prevent this sort of access. Do others set the DHCP to only issue to registered MAC address table?

 

Any guidance would be great!

 

Thanks

 

Gareth

Posted
what switches are you using? port security is an option. it wirks on mac addresses so if a user unpluggs a pc to plug their laptop in it either disables the port or ignores the laptop that's plugged in, i know hp and cisco support this not too sure about other brands
  • Thanks 1
Posted

Yeah we've got HP Procurves, they're managed by the LEA but that sounds exactly what we'd want to implement. I'll fire off an email to them and ask about it.

Thanks

Posted
Find in DHCP and add to disallow filter. They won't be able to connect again. Time consuming and they have to have connected once all ready, but worth it if they are repeat offenders.
  • Thanks 1
Posted

To be honest however you push out proxy settings it would be possible for someone to gain those details so I wouldn't hang too much on that as an issue.

 

I've used RJ45 locks in the past although they can be broken off.

 

You could look in to a NAC solution such as Counteract, this would effectively control what machines are able to connect and where.

 

Ben

Posted (edited)

Do you allow guests access?

 

If not, What about using DHCP classes.

 

I'm going to try it here to set guests to use a different gateway.

 

Roll out a script to change the class on all of your machines and then change the default classes setting to give out duff settings.

 

Or just check dhcp every so often and ban them.

 

Problem with anything done in dhcp is that can be easily got round with a static IP if they are able to find the details.

Edited by DCUK6
Posted
Or give them wifi access with captive portal implemented with RADIUS.

 

Not quite as simple as that. SLT might not want it etc.

  • Thanks 1
Posted

Thanks for the tips, couple options. I await the LEA's ideas but was more worried if it was something other schools were doing and we're not but sounds like most already doing the DHCP block option after the event.

 

Have Ruckus for the Wireless and will be doing a captive portal on there for Students. I've suggested the best option would be allow them to use the Wifi (Much like @cpjitservices suggests) so we'd have more control on what devices are on the Network and easily VLanned from the rest of the network. However, FN-GM is right, SLT are the issue with that and Network ports still vulnerable.

 

Any spare ports are unpatched, so perhaps just need to keep better eye on the DHCP logs and get SLT to come down hard on Students abusing it.

 

Thanks for the advice though!

  • Thanks 1
Posted
I don't know if it is still in place, but I was using 802.1x for client authentication (and VLAN assignment) along with an unauthenticated VLAN with limited services.
Posted

We don't patch the ports that aren't in use. Leaving them secure. Then for the desktops and printers. we have lockable network cables. Require a key to unlock them.

 

They are fantastic! But expensive!

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...