Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

Recommended Posts

Posted

Hi all,

 

Just wondering is there any documented way I can prevent 'contractors' plugging in domestic/unmanaged switches in an otherwise managed network? I have ruled out cutting their arms off and looking for a simpler way.

 

Without getting too specific, 'some' phone companies think it's smart to install £20 unmanaged switches, to get around capacity issues (such as installing phones or other), rather than installing a new CAT5/CAT6 feed to the required location. It's quicker, cheaper and they make more profits.

 

Consequently when said unmanaged switch becomes faulty, it's 'my fault' this has happened :rolleyes:

Posted

Definitely possible, but I've only experienced it as a user so unfortunately no idea how to implement.

 

A company I used to work for had a system where all devices connecting to their LAN had to be authorised. Plugging in any unauthorised devices caused the port to shut down immediately. It automatically reactivated a few hours later.

 

This was before WiFi was widespread. I used to carry a £10 8 port switch so that we could get online in meeting rooms with a single LAN port (which was most of them). Flippin' IT support blockers stopping me from working [emoji14]

Posted

Make sure all traffic is tagged between switches and up link ports are configured as Trunk not auto. Edge ports are set as Edge not auto.

Do not use vLAN 1

 

Just trying to think of ways that would stop a unmanaged switch working from the offset.

 

Port security is another option if available but will be an admin overhead.

Posted

This is the thing, there's no real easy solution to this... and I don't want to enable anything that will cause additional overhead.

 

Of course one other solution is shutting down unused ports.

Posted

You can limit the number of Mac addresses on a port. If more than the specified number appear on the port one of the following can happen depending on what you want to do.

 

1. The port shuts down. With optional auto recovery.

2. The switch will drop traffic from mac addresses that appear at and after the specified limit. Mac addresses connected to the port before the limit is reached carry on working as usual.

 

The added bonus is this will protect against mac overflow attacks.

Posted
Well I have STP enabled throughout which comes up a lot in Google searches. I guess I'm posting here to see how others 'tackle' this issue.
Posted
Well I have STP enabled throughout which comes up a lot in Google searches. I guess I'm posting here to see how others 'tackle' this issue.

 

STP combined with BPDU guard would work for managed switches. But unmanaged switches do not run STP so no BPDU's so will be ignored. In this instance it won't make a difference. The only time STP (again with BPDU gaurd) would work if the unmanaged switch has a loop.

Posted (edited)

Limit the number of Mac Addresses on a port to 1 will stop those unmanaged switches.

 

You can configure it on a port by port basis if you wanted.

Edited by FN-GM
  • Thanks 1
Posted
Limit the number of MAC addresses on a port to 1 will stop those unmanaged switches.

There's also the "sticky" MAC address feature that a lot of managed switches have.

 

https://www.freeccnaworkbook.com/workbooks/ccna/configuring-sticky-switchport-security

 

Dynamic port security is great but what about when you connect switches to routers or other devices that need to be secured in a way to prevent unauthorized device swapping in the network. For example you have a small site location with a 1841 router and a 3560-8pc switch and an end user gets the bright idea to swap the 1841 with a WRT54G because he wants wireless and wired network connectivity.

 

In this case you can sticky the port that the wan router is connected to preventing unauthorized device swaps like such.

 

There are two ways to configure a sticky port. The first way being that you configure a static MAC address when configuring port-security on a specific interface. The next way which is more convenient is to configure a “Sticky” MAC address and leave the max MAC addresses to its default value of one. When port-security is configured this way, the first MAC address learned on the switch port will be automatically statically configured into the running-configuration as if you manually specified the MAC address.

Posted
I would configure it to limit to 1 mac address and set an ageing time of 2 mins of inactivity. That way it will forget the mac address after the machine has been disconnected after 2 mins and ready to accept a new one. If there is a violation (IE more than 1 mac) it will drop the packets from the second Mac. Will solve the unmanaged switch issue with little fuss.
  • Thanks 1
Posted

Make it clear in any plan of works that doing so will result in the invoice being unpaid until they do it properly.

 

As in "All phone points should connect directly back to $whereever. School policy forbids the use of unmanaged switches."

 

If they ignore that, cancel the contract/work - they failed to follow client instructions.

Posted
Also remember that all 3rd party systems on your network are insecure, use default passwords, and are never updated. Should probably test them for exploits, then ban them from the network until they're fixed. Have it in your contract that they pay for security fixes.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...