Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 48 guests and 1 member online
 
Free Business and Tech Magazines and eBooks

You are here: Home arrow Ethical Hacking Discussions and Related Certificationsarrow Network Pen Testingarrow 'Outsider' Network Access
EH-Net
May 20, 2013, 12:55:10 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Go back to The Ethical Hacker Network Online Magazine Home Page
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: 'Outsider' Network Access  (Read 5270 times)
0 Members and 1 Guest are viewing this topic.
BillV
Hero Member
*****
Offline Offline

Posts: 1892


View Profile WWW
« on: August 07, 2008, 12:53:23 PM »

How does everyone secure their network from insider 'outsider' access? When I say outsider, I'm talking about people giving presentations, consultants and others who are supposed to be in your office but are requesting Internet access. Do you have a strict policy to forbid them access entirely? Have some way to give them limited access? Any other policies?

We have some inventory software that scans our network and will show when other workgroups/domains have been connected. It came up recently and I brought this to the attention of our IT Director stating that some other computers had been connected to our network. She asked for some suggestions on how to control this, so I figured I'd ask here to see what everyone else does. My thoughts are to hook up a switch or wireless access point to a separate port on our firewall and just segment all the traffic off from the internal network. That way they can get access to the Internet, but nothing else. If it were my choice, I wouldn't even allow them to connect Wink but I don't think that will fly Sad

BillV
Logged
oldgrue
Newbie
*
Offline Offline

Posts: 13


View Profile
« Reply #1 on: August 07, 2008, 02:33:50 PM »

I think you're best to isolate their access like you've suggested. I'd suggest against the wireless so you don't have staff connecting personal devices to it.

It might be better if you can isolate their work areas (especially if you have longer term contractors) and hardwire the connection to a switch instesd.
Logged
BillV
Hero Member
*****
Offline Offline

Posts: 1892


View Profile WWW
« Reply #2 on: August 07, 2008, 03:39:53 PM »

I think you're best to isolate their access like you've suggested. I'd suggest against the wireless so you don't have staff connecting personal devices to it.

It might be better if you can isolate their work areas (especially if you have longer term contractors) and hardwire the connection to a switch instesd.

Thanks Smiley

If we do the wireless it won't be open and we'll probably change the password fairly frequently so anyone wanting access will have to come ask us. That way anyone wanting access will be required to come through us first Grin
Logged
sgt_mjc
Sr. Member
****
Offline Offline

Posts: 294


View Profile
« Reply #3 on: August 07, 2008, 04:03:47 PM »

I think that is how we handle it here. I can see several "guest" APs here that are secured and I'm more than willing to bet that that is what they are used for. Those of that work here can plug in to the corporate network from the conference rooms. Good luck, Bill.
Logged

Mike Conway
CISSP
CompTia Security +
C|EH
Andrew Waite
Hero Member
*****
Offline Offline

Posts: 928



View Profile WWW
« Reply #4 on: August 08, 2008, 02:28:18 AM »

Billv,

we have a seperate wireless system for outsiders. It runs through a proxy requiring a 'voucher' to bypass the landing page. If a third party needs internet access they get a time-limited voucher, if an employee needs access they get the (frequently changed) WPA key. Keeps the two sets isolated nicely.
Logged

BillV
Hero Member
*****
Offline Offline

Posts: 1892


View Profile WWW
« Reply #5 on: August 08, 2008, 07:20:34 AM »

Thanks for the replies guys. Sounds like that's probably where we'll focus our efforts.
Logged
RobMongoose
Newbie
*
Offline Offline

Posts: 28



View Profile WWW
« Reply #6 on: August 09, 2008, 07:48:24 PM »

Maybe for wired connections you could set up a switch connected to a restricted access vlan, then you could attach a wireless access point configured, as others have suggested, to provide a separate wireless network to this switch. That should be nice and secure.
Logged

Mutterings of an evil genius in training -
http://robmongoose.blogspot.com/
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.18 | SMF © 2013, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.088 seconds with 22 queries.
 
Exclusive Deal

sansfire13_245x90_cw90.jpg
SANSFIRE 2013
June 15 - 22

5% Off w/ Code: EHN_5

SANS Deals 4 EH-Netters
5% OFF Any SANS Course in Any Format!
Coupon Code: EHN_5 Including SANS Rocky Mountain 2013 & SANS Boston 2013
Polls
Compared to this year, 2013 will be:
 
Recent Forum Topics
EH-Net News Feeds
Latest Additions
 
         
Free Business and Tech Magazines and eBooks

© 2013 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.