Jump to content

Recommended Posts

Posted

To my surprise we ran out of IP addresses this morning.

 

On closer inspection It looks like the kids are connecting their wireless devices to our network and taking up loads of Ips.

 

Image1.jpg

 

Now I realize that I can't ever keep the wireless key totally secure so I'm looking at different ways to tackle the problem?

 

Is there any way to stop names like "ipod" getting a DHCP address?

 

What about stopping them getting an address from our managed wireless aruba system?

 

Anything I'm missing?

Posted

theres another thread about this on here atm but basically iirc it boiled down to 2 simple solutions

 

if you have 08r2 server you can add the device to a block list by right clicking its lease and add to filter deny

 

if you dont have 08 r2 give it a reserved ip in a silly range so say 99.99.99.101

Posted

Thanks for all the advice, It was surprisingly easy with the Microsoft macfilter DLL

 

I'll write a blog post about it later.

 

This method is a little tedious but gives me lots of control over who connects to the network.

Posted
Why not, only IT support staff know ours.

 

The kids have obviously found a way to get it. I'd imagine they simply use wirelesskeyview.exe on any client in the school.

 

It tells you the wireless key right away, there's no way I could stop that happening easily.

  • Thanks 1
Posted
The kids have obviously found a way to get it. I'd imagine they simply use wirelesskeyview.exe on any client in the school.

 

It tells you the wireless key right away, there's no way I could stop that happening easily.

 

what type of key are you using?

Posted
what type of key are you using?

 

WPA2.

 

That utility doesn't crack it though.

 

It simply reads the key from the windows registry on any client that has it stored.

Posted
Yes - as nephilim has said mac address filter - I use a white list (only devices registered with me) on the access points. Unauthorised clients just fail to associate.
Posted
It tells you the wireless key right away, there's no way I could stop that happening easily.

Unless you have an uptodate version of Sophos, which blocks it as "adware/PUA 'NirSoft'"

 

What about stopping them getting an address from our managed wireless aruba system?

 

Anything I'm missing?

Surely on a managed system the security should be dealt with by AD via PEAP etc anyways...? Sounds like the system hasn't been configured correctly. Our Trapeze system only allows domain members access, and only if those members are within a specific machine group.

 

Here, even the IT Support team don't know the wireless key...!

Posted
WPA2.

 

That utility doesn't crack it though.

 

It simply reads the key from the windows registry on any client that has it stored.

 

Well i would block the students from running .exe file (loads of threads on here about it) Once you have done that change your key.

Posted
The best way, if you've got the time, is to change your wireless authentication to use a RADIUS server with machine only authentication. Not only can you then distribute the wireless settings via Group Policy, but you can also control very easily who does and doesn't have access to your wireless network. :)
Posted
Yes - as nephilim has said mac address filter - I use a white list (only devices registered with me) on the access points. Unauthorised clients just fail to associate.

 

Ahhhh! Mac Filtering is one of the worst systems in existence, not because it's inherently an insecure system, but because everyone thinks it's bulletproof. Honestly a Mac is easy to spoof as one two three these days. Thinking that Mac filtering is a good mindset is not a good mindset at all. :( And no, it won't suffice for iPhones/iPods/Android either, you can spoof on them too I hear. Stop using WPA2 only, use certificates on the machines as well, perhaps under a different SSID to the ones that don't support certificates. My college has a Trusted, Guest and Other SSID, Guest is open and has a captive portal, Trusted requires WPA2 and a valid certificate, Other I'm not even sure what it's used for to be honest. And yeah, that's an Aruba system.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...