animalboy1968 Posted April 16, 2007 Posted April 16, 2007 sorry to join the forum late but have you seen this? http://www.vmware.com/products/ace/ the brilliant idea is that you create a vmware machine inside their laptop which you have full admin rights to and they do not. this way you are only responsible for the content on the vmware machine and they are able to do whatever they want on the laptop. it will even check av defs & allow users access to certain parts of the network depending on their logon etc. if you are still contemplating a solution i would advise you to read it. we don't allow students to bring in their laptops from home so i can't play with this myself but i hear it is very popular in universities around the country
Ric_ Posted April 16, 2007 Posted April 16, 2007 @animalboy1968: A good idea however it can prove expensive... hence why I do it the opposite way around and use VMWare Player for staff. I create a VM on my workstation and they can use that for testing demos, etc. while the networked settings remain.
Geoff Posted April 16, 2007 Posted April 16, 2007 I take it you have used Snort Geoff ? It's running on my border firewall and also on the externally facing web server (although that one is limited to web related IDS signatures). It's also a component in Packetfence, an open source NAC solution I'm playing with.
FN-GM Posted June 19, 2007 Posted June 19, 2007 Dual boot them. Have one partition running the XP Home that comes with the laptop for use at home...and have the other partition running your volume licensed copy of XP Pro that you'd use for your on-site machines etc. That way it's /sort/ of kept separate and you can have them hooked up to the network. There's not much point in offereing laptops for students if they cant use them onsite too when they cant get onto a workstation in the library etc IMHO. What a good idea
Andi Posted June 19, 2007 Posted June 19, 2007 Our school is a boarding school so I guess works much in the same way as many halls of residence. Until now boys have been able to plug into the network point in their room, they get assigned an IP via the domain DHCP and away they go. The only real bit of security we have setup is only one MAC address is allowed to plug into that port using the managed switch. This setup gives me shivers as although they aren't on our domain, they are still in the same address range. Ideally what I want to do is setup a VLAN for their ports giving them a completely different IP range which only gives them access to the terminal server or the internet. I'm not quite sure how to set this up, but it's definitely one of the projects I want to get started on asap.
Andi Posted June 19, 2007 Posted June 19, 2007 Is that the kind of tool that would help me route their traffic after they're VLan'd? I'll look into that, thanks Geoff.
Geoff Posted June 19, 2007 Posted June 19, 2007 Is that the kind of tool that would help me route their traffic after they're VLan'd? A hardware firewall. Be aware though that VLANs aren't an effective security measure against a determined attacker. Air gap your networks if possible,
NickyD Posted November 4, 2009 Posted November 4, 2009 Have you got a copy of the laptop agreement as I am about to write one.
Gatt Posted November 4, 2009 Posted November 4, 2009 Has anyone successfully implemented NAP to try and stop this from happenening - IIRC it can be set up so taht only Domain Members can connect to the network - all non domain laptops, etc either cannot connect or get a limited conection Not had a chance to play yet though going to look into it shortly
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now