Jump to content

Recommended Posts

Posted

Hi all

 

Has anyone ever come across a company who put in place an 11.x.x.x IP as the internal range?

 

I have just started contracting for a new school, whose framework providers have done just this.

 

Clearly this is not best practice, and their excuse for doing so is that, because people know full well the scope of internal ranges, this is more secure?!?!

 

I just wondered if any of you have encountered this before, and if so, what, if anything, you did about it.

 

Many thanks.

Posted (edited)
because people know full well the scope of internal ranges, this is more secure?!?!

 

Rubbish!!

 

The only time I have seen this is when the company owned the public address range they used internally. This meant they didn't have to use NAT. This is also very common with IPv6. This scenario is perfectly fine. However if they don't own the public range they are using internally (doubt it for a new school) its a big no no. If they need to access resources on a public server that has an IP falling within their internally used IP range they won't be able to access it.

 

Hiding your internal IP address does not help security any qualified networking or security professional will tell you that. Infact NAT to "hide" private IP addresses can inadvertently cause security issues.

Edited by FN-GM
  • Thanks 1
Posted
Rubbish!!

 

The only time I have seen this is when the company owned the public address range they used internally. This meant they didn't have to use NAT. This is also very common with IPv6. This scenario is perfectly fine. However if they don't own the public range they are using internally (doubt it for a new school) its a big no no. If they need to access resources on a public server that has an IP falling within their internally used IP range they won't be able to access it.

 

Hiding your internal IP address does not help security any qualified networking or security professional will tell you that. Infact NAT to "hide" private IP addresses can inadvertently cause security issues.

 

This is my point exactly. In fact, the IP range in question is owned by a dept of the US DoD!!

Posted
This is my point exactly. In fact, the IP range in question is owned by a dept of the US DoD!!

 

Well - I suppose that at least makes it unlikely that you would be trying to access the IP addresses on the external internet

 

but still......

 

 

(unless the school is secretly a part of the CIA???????????????)

  • Thanks 1
Posted
I'd bring it up and force the issue personally. There's no reason for it.

 

Oh, I have - hence the ridiculous response they issued.

 

I am writing to the Principal listing a number of findings, the main one of which is this matter.

Posted
Yes, the schools associated with the Newcastle Council Managed IT Service all have public IPs being used inappropriately internally.

 

Have they stated why?

Posted

I'd say this is one of the signs of why the school asked you to start contracting for them.

 

I've seen it before and it was merely the tip of the completely pants-on-head iceberg.

  • Thanks 1
Posted
I'd say this is one of the signs of why the school asked you to start contracting for them.

 

I've seen it before and it was merely the tip of the completely pants-on-head iceberg.

 

Yeah. They also put in a backup solution which consists entirely of a NAS in the same cabinet as the server/SAN!! 3-2-1 to them means Dusty Bin I think :-(

Posted

A school I was at many moons ago had public ranges in use, partly to allow for VC to be used ad-hoc and a range of other reasons.

We slowly but surely moved over to private ranges and handed the bulk of the public ranges back.

To use a public range belonging to someone else is shameful and asking for problems.

It could be worse ... you could also be using the domain belonging to someone else too!

  • Thanks 1
Posted
It could be worse ... you could also be using the domain belonging to someone else too!

 

Maybe he's saving the Contoso post for BTRD?

Posted
A school I was at many moons ago had public ranges in use, partly to allow for VC to be used ad-hoc and a range of other reasons.

We slowly but surely moved over to private ranges and handed the bulk of the public ranges back.

To use a public range belonging to someone else is shameful and asking for problems.

It could be worse ... you could also be using the domain belonging to someone else too!

 

This is a Framework provider as well...could not believe what I was seeing.

Posted
It's funny. I was playing with an IoT type device the other week that had the same range applied - 11.11.11.100 I think it was set to. This address was also fixed in the android app which connected to it!
Posted
I suspect it is to add another stream of income for the company. Adding an extra private IP is free, but for public you'll have buy these extra IP addresses when needed.
Posted
Have they stated why?

 

It is apparently a legacy issue dating back a long time to when an external contractor was hired to manage the installation of all the school networks. They haven't done anything about fixing it however. In fact they have moved schools into new buildings with completely new equipment and brought over the legacy issue of public IPs being used inappropriately.

 

They're using ranges that are owned by others.

Posted
I suspect it is to add another stream of income for the company. Adding an extra private IP is free, but for public you'll have buy these extra IP addresses when needed.

 

I don't think the US DoD are selling many IPs off to UK schools personally!

Posted
Aha, i missed that bit. It's probably down to lazy admins then, the assumption that 11... will never go public and is therefore usable.
Posted
Has anyone ever come across a company who put in place an 11.x.x.x IP as the internal range?

 

Seen this done before. I quite like people doing stuff like that because it is much easier to fire a company that makes it so obvious that they don't know what they are doing. :)

 

Clearly this is not best practice, and their excuse for doing so is that, because people know full well the scope of internal ranges, this is more secure?!?!

 

Anyone on your internal network will easily be able to see what addresses you're using anyway. Anyone outside your network won't be able to contact your internal addresses, even if they know what they are. And besides, obfuscating your network doesn't get you any meaningful security, but it does make it harder to maintain (which in turn means you're more likely to leave a gaping security hole somewhere :)

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...