Gibson335 Posted January 9, 2017 Posted January 9, 2017 Hi all Has anyone ever come across a company who put in place an 11.x.x.x IP as the internal range? I have just started contracting for a new school, whose framework providers have done just this. Clearly this is not best practice, and their excuse for doing so is that, because people know full well the scope of internal ranges, this is more secure?!?! I just wondered if any of you have encountered this before, and if so, what, if anything, you did about it. Many thanks.
FN-GM Posted January 9, 2017 Posted January 9, 2017 (edited) because people know full well the scope of internal ranges, this is more secure?!?! Rubbish!! The only time I have seen this is when the company owned the public address range they used internally. This meant they didn't have to use NAT. This is also very common with IPv6. This scenario is perfectly fine. However if they don't own the public range they are using internally (doubt it for a new school) its a big no no. If they need to access resources on a public server that has an IP falling within their internally used IP range they won't be able to access it. Hiding your internal IP address does not help security any qualified networking or security professional will tell you that. Infact NAT to "hide" private IP addresses can inadvertently cause security issues. Edited January 9, 2017 by FN-GM 1
Gibson335 Posted January 9, 2017 Author Posted January 9, 2017 Rubbish!! The only time I have seen this is when the company owned the public address range they used internally. This meant they didn't have to use NAT. This is also very common with IPv6. This scenario is perfectly fine. However if they don't own the public range they are using internally (doubt it for a new school) its a big no no. If they need to access resources on a public server that has an IP falling within their internally used IP range they won't be able to access it. Hiding your internal IP address does not help security any qualified networking or security professional will tell you that. Infact NAT to "hide" private IP addresses can inadvertently cause security issues. This is my point exactly. In fact, the IP range in question is owned by a dept of the US DoD!!
FN-GM Posted January 9, 2017 Posted January 9, 2017 This is my point exactly. In fact, the IP range in question is owned by a dept of the US DoD!! :doh: 1
mikeprice Posted January 9, 2017 Posted January 9, 2017 This is my point exactly. In fact, the IP range in question is owned by a dept of the US DoD!! Well - I suppose that at least makes it unlikely that you would be trying to access the IP addresses on the external internet but still...... (unless the school is secretly a part of the CIA???????????????) 1
jinnantonnixx Posted January 9, 2017 Posted January 9, 2017 Yes, I've seen this before, and yes, it is ridiculous. End of discussion. 1
Blue_Cookeh Posted January 9, 2017 Posted January 9, 2017 I'd bring it up and force the issue personally. There's no reason for it. 1
Gibson335 Posted January 9, 2017 Author Posted January 9, 2017 I'd bring it up and force the issue personally. There's no reason for it. Oh, I have - hence the ridiculous response they issued. I am writing to the Principal listing a number of findings, the main one of which is this matter.
Primus Posted January 9, 2017 Posted January 9, 2017 Yes, the schools associated with the Newcastle Council Managed IT Service all have public IPs being used inappropriately internally.
Gibson335 Posted January 9, 2017 Author Posted January 9, 2017 Yes, the schools associated with the Newcastle Council Managed IT Service all have public IPs being used inappropriately internally. Have they stated why?
FN-GM Posted January 9, 2017 Posted January 9, 2017 I think this should be one for the IT Support Confessions group on Facebook. 1
pete Posted January 9, 2017 Posted January 9, 2017 I'd say this is one of the signs of why the school asked you to start contracting for them. I've seen it before and it was merely the tip of the completely pants-on-head iceberg. 1
Gibson335 Posted January 9, 2017 Author Posted January 9, 2017 I'd say this is one of the signs of why the school asked you to start contracting for them. I've seen it before and it was merely the tip of the completely pants-on-head iceberg. Yeah. They also put in a backup solution which consists entirely of a NAS in the same cabinet as the server/SAN!! 3-2-1 to them means Dusty Bin I think :-(
jinnantonnixx Posted January 9, 2017 Posted January 9, 2017 (edited) You read about this sort of stuff on this site. The Daily WTF: Curious Perversions in Information Technology Edited January 9, 2017 by jinnantonnixx 1
GrumbleDook Posted January 9, 2017 Posted January 9, 2017 A school I was at many moons ago had public ranges in use, partly to allow for VC to be used ad-hoc and a range of other reasons. We slowly but surely moved over to private ranges and handed the bulk of the public ranges back. To use a public range belonging to someone else is shameful and asking for problems. It could be worse ... you could also be using the domain belonging to someone else too! 1
pete Posted January 9, 2017 Posted January 9, 2017 It could be worse ... you could also be using the domain belonging to someone else too! Maybe he's saving the Contoso post for BTRD?
Gibson335 Posted January 9, 2017 Author Posted January 9, 2017 A school I was at many moons ago had public ranges in use, partly to allow for VC to be used ad-hoc and a range of other reasons. We slowly but surely moved over to private ranges and handed the bulk of the public ranges back. To use a public range belonging to someone else is shameful and asking for problems. It could be worse ... you could also be using the domain belonging to someone else too! This is a Framework provider as well...could not believe what I was seeing.
jinnantonnixx Posted January 9, 2017 Posted January 9, 2017 When your data is stored in a database called 'Northwinds' then it's time to leave.
IrritableTech Posted January 9, 2017 Posted January 9, 2017 It's funny. I was playing with an IoT type device the other week that had the same range applied - 11.11.11.100 I think it was set to. This address was also fixed in the android app which connected to it!
win Posted January 9, 2017 Posted January 9, 2017 I suspect it is to add another stream of income for the company. Adding an extra private IP is free, but for public you'll have buy these extra IP addresses when needed.
Primus Posted January 9, 2017 Posted January 9, 2017 Have they stated why? It is apparently a legacy issue dating back a long time to when an external contractor was hired to manage the installation of all the school networks. They haven't done anything about fixing it however. In fact they have moved schools into new buildings with completely new equipment and brought over the legacy issue of public IPs being used inappropriately. They're using ranges that are owned by others.
Blue_Cookeh Posted January 9, 2017 Posted January 9, 2017 I suspect it is to add another stream of income for the company. Adding an extra private IP is free, but for public you'll have buy these extra IP addresses when needed. I don't think the US DoD are selling many IPs off to UK schools personally!
win Posted January 9, 2017 Posted January 9, 2017 Aha, i missed that bit. It's probably down to lazy admins then, the assumption that 11... will never go public and is therefore usable.
SchoolsBroadband Posted January 9, 2017 Posted January 9, 2017 Going back many years ago I once saw a school with an 8.0.0.0/8 subnet mask. Genius when many of Googles services are in there Dave
Opendium_Steve Posted January 13, 2017 Posted January 13, 2017 Has anyone ever come across a company who put in place an 11.x.x.x IP as the internal range? Seen this done before. I quite like people doing stuff like that because it is much easier to fire a company that makes it so obvious that they don't know what they are doing. Clearly this is not best practice, and their excuse for doing so is that, because people know full well the scope of internal ranges, this is more secure?!?! Anyone on your internal network will easily be able to see what addresses you're using anyway. Anyone outside your network won't be able to contact your internal addresses, even if they know what they are. And besides, obfuscating your network doesn't get you any meaningful security, but it does make it harder to maintain (which in turn means you're more likely to leave a gaping security hole somewhere
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now