Jump to content

Recommended Posts

Posted

I was reading some whitepapers the other day of Microsoft’s web site about IPSec and wondered if it would be a good way to stop LAN side attacks / unwanted student laptops gaining access to vulnerable services by just jacking in to a RJ45 point. Now we haven’t had any issues yet but I don’t want it to happen on my watch so to say, and just wondered if anyone had implemented this before, what the pitfalls are.

For ref we have 5 W2k3 servers all R2 and all clients are XP or W2K. Oh yeah and a couple of HP PDAs running Windows Mobile 2003

Posted
By definition IPsec works at layer3. In addition to this, security on the switches should be enabled - each port associated with a MAC address would prevent unknown laptops from connecting to the network.
Posted
Have a look at 802.1X authentication if you want to prevent people connecting random devices to your LAN. It works the same way as WPA with wireless access points using Radius (IAS in windows speak). Your switches need to support radius authentication however.
Posted
Thanks Guys I’ll have a look at 802.1x I just upgraded my switches last summer to Netgear Layer2 Managed switches... so I hope they support it... otherwise its a non starter cause I’m not replacing them this year

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...