zag Posted November 10, 2010 Posted November 10, 2010 To my surprise we ran out of IP addresses this morning. On closer inspection It looks like the kids are connecting their wireless devices to our network and taking up loads of Ips. Now I realize that I can't ever keep the wireless key totally secure so I'm looking at different ways to tackle the problem? Is there any way to stop names like "ipod" getting a DHCP address? What about stopping them getting an address from our managed wireless aruba system? Anything I'm missing?
FN-GM Posted November 10, 2010 Posted November 10, 2010 Now I realize that I can't ever keep the wireless key totally secure Why not, only IT support staff know ours.
sted Posted November 10, 2010 Posted November 10, 2010 theres another thread about this on here atm but basically iirc it boiled down to 2 simple solutions if you have 08r2 server you can add the device to a block list by right clicking its lease and add to filter deny if you dont have 08 r2 give it a reserved ip in a silly range so say 99.99.99.101
Jonny Posted November 10, 2010 Posted November 10, 2010 Microsoft provides some helpful guides to ensure that only domain member clients are logging onto your network. Try the link below: Securing Wireless LANs with PEAP and Passwords
Iain Posted November 10, 2010 Posted November 10, 2010 Take a look at some kind of Network Access Control, such as Microsoft's NAP (Network Access Protection), or PacketFence (PacketFence: Open Source NAC (Network Access Control)) Iain.
zag Posted November 10, 2010 Author Posted November 10, 2010 Thanks for all the advice, It was surprisingly easy with the Microsoft macfilter DLL I'll write a blog post about it later. This method is a little tedious but gives me lots of control over who connects to the network.
zag Posted November 10, 2010 Author Posted November 10, 2010 Why not, only IT support staff know ours. The kids have obviously found a way to get it. I'd imagine they simply use wirelesskeyview.exe on any client in the school. It tells you the wireless key right away, there's no way I could stop that happening easily. 1
FN-GM Posted November 10, 2010 Posted November 10, 2010 The kids have obviously found a way to get it. I'd imagine they simply use wirelesskeyview.exe on any client in the school. It tells you the wireless key right away, there's no way I could stop that happening easily. what type of key are you using?
zag Posted November 10, 2010 Author Posted November 10, 2010 what type of key are you using? WPA2. That utility doesn't crack it though. It simply reads the key from the windows registry on any client that has it stored.
featured_spectre Posted November 10, 2010 Posted November 10, 2010 MAC Address block them all, that way they will never be able to connect
Hedghog Posted November 10, 2010 Posted November 10, 2010 Yes - as nephilim has said mac address filter - I use a white list (only devices registered with me) on the access points. Unauthorised clients just fail to associate.
Marci Posted November 10, 2010 Posted November 10, 2010 It tells you the wireless key right away, there's no way I could stop that happening easily. Unless you have an uptodate version of Sophos, which blocks it as "adware/PUA 'NirSoft'" What about stopping them getting an address from our managed wireless aruba system? Anything I'm missing? Surely on a managed system the security should be dealt with by AD via PEAP etc anyways...? Sounds like the system hasn't been configured correctly. Our Trapeze system only allows domain members access, and only if those members are within a specific machine group. Here, even the IT Support team don't know the wireless key...!
FN-GM Posted November 10, 2010 Posted November 10, 2010 WPA2. That utility doesn't crack it though. It simply reads the key from the windows registry on any client that has it stored. Well i would block the students from running .exe file (loads of threads on here about it) Once you have done that change your key.
zag Posted November 10, 2010 Author Posted November 10, 2010 Thanks for the suggestions, definitely going to look at banning wirelesskey.exe to stop the problem at cause as well. Blog post. http://www.edugeek.net/blogs/zag/533-banning-ipods-blackberries-androids-home-laptops-your-school-network.html
FN-GM Posted November 10, 2010 Posted November 10, 2010 Also if your running out of IP's change your lease time this will help. Ours is set to 8 hours.
CyberNerd Posted November 10, 2010 Posted November 10, 2010 use a separate VLAN and DHCP scope for staff and student devices.
maniac Posted November 10, 2010 Posted November 10, 2010 The best way, if you've got the time, is to change your wireless authentication to use a RADIUS server with machine only authentication. Not only can you then distribute the wireless settings via Group Policy, but you can also control very easily who does and doesn't have access to your wireless network.
Cue Posted November 10, 2010 Posted November 10, 2010 Yes - as nephilim has said mac address filter - I use a white list (only devices registered with me) on the access points. Unauthorised clients just fail to associate. Ahhhh! Mac Filtering is one of the worst systems in existence, not because it's inherently an insecure system, but because everyone thinks it's bulletproof. Honestly a Mac is easy to spoof as one two three these days. Thinking that Mac filtering is a good mindset is not a good mindset at all. And no, it won't suffice for iPhones/iPods/Android either, you can spoof on them too I hear. Stop using WPA2 only, use certificates on the machines as well, perhaps under a different SSID to the ones that don't support certificates. My college has a Trusted, Guest and Other SSID, Guest is open and has a captive portal, Trusted requires WPA2 and a valid certificate, Other I'm not even sure what it's used for to be honest. And yeah, that's an Aruba system.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now