Jump to content

Recommended Posts

Posted

sorry to join the forum late but have you seen this?

 

http://www.vmware.com/products/ace/

 

the brilliant idea is that you create a vmware machine inside their laptop which you have full admin rights to and they do not. this way you are only responsible for the content on the vmware machine and they are able to do whatever they want on the laptop. it will even check av defs & allow users access to certain parts of the network depending on their logon etc. if you are still contemplating a solution i would advise you to read it. we don't allow students to bring in their laptops from home so i can't play with this myself but i hear it is very popular in universities around the country

Posted
@animalboy1968: A good idea however it can prove expensive... hence why I do it the opposite way around and use VMWare Player for staff. I create a VM on my workstation and they can use that for testing demos, etc. while the networked settings remain.
Posted
I take it you have used Snort Geoff ?

 

It's running on my border firewall and also on the externally facing web server (although that one is limited to web related IDS signatures).

 

It's also a component in Packetfence, an open source NAC solution I'm playing with.

  • 2 months later...
Posted
Dual boot them. Have one partition running the XP Home that comes with the laptop for use at home...and have the other partition running your volume licensed copy of XP Pro that you'd use for your on-site machines etc.

 

That way it's /sort/ of kept separate and you can have them hooked up to the network. There's not much point in offereing laptops for students if they cant use them onsite too when they cant get onto a workstation in the library etc IMHO.

 

What a good idea

Posted

Our school is a boarding school so I guess works much in the same way as many halls of residence.

 

Until now boys have been able to plug into the network point in their room, they get assigned an IP via the domain DHCP and away they go. The only real bit of security we have setup is only one MAC address is allowed to plug into that port using the managed switch.

 

This setup gives me shivers as although they aren't on our domain, they are still in the same address range.

 

Ideally what I want to do is setup a VLAN for their ports giving them a completely different IP range which only gives them access to the terminal server or the internet. I'm not quite sure how to set this up, but it's definitely one of the projects I want to get started on asap.

Posted

Is that the kind of tool that would help me route their traffic after they're VLan'd?

 

I'll look into that, thanks Geoff.

Posted
Is that the kind of tool that would help me route their traffic after they're VLan'd?

 

A hardware firewall. Be aware though that VLANs aren't an effective security measure against a determined attacker. Air gap your networks if possible,

  • 2 years later...
Posted

Has anyone successfully implemented NAP to try and stop this from happenening - IIRC it can be set up so taht only Domain Members can connect to the network - all non domain laptops, etc either cannot connect or get a limited conection

 

Not had a chance to play yet though going to look into it shortly

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...