Firewall Wizards mailing list archives
Re: Securing a wireless network
From: Tony Rall <trall () almaden ibm com>
Date: Fri, 29 Oct 2004 18:19:37 -0700
On Friday, 2004-10-29 at 15:55 AST, <chris () compucounts com> wrote:
The network in question is in a public high school (hence 'so-called place of business'). The users are faculty, staff, students, and any hobo around the corner with a laptop and a wireless card. We have next to no control over end user devices, because almost everybody brings their own. The networked computers are almost entirely Windows based; we don't care about the half dozen Macs. There is very little concern for traditional security in this environment. Confidentiality is not an issue and quite frankly, I would welcome a MITM attack - it would be something new around here. Accounting is based on IP address - 1 year leases. Those with enough knowledge to bypass the http proxy and this "accounting" method are also (usually) smart enough to not look at porn in front of their teachers. Although there have been some exceptions to this (funny!!). The general idea here is that if you know enough to bypass our lack of security, you deserve to do so. Best practices? Don't start - These are the wishes of a school system completely unwilling to change. Nobody has any sense of security around here. My only goal is to make sure the laptops that go in and out of here on a daily basis don't bring every strain of Bagle, Netsky, Sasser or herpes into this place. I would rather enforce the use of condoms than preach abstinence in vain and play doctor every day. ** So far, I've gotten several suggestions about Cisco's Network Admission Control and the Cisco Trust Agent. I'm looking into this and it looks promising. Hopefully someone in engineering has a cisco account so we can download the goodies.
Is this really only related to wireless "connections"? I think most of the issues apply to wired connections also. It's still not clear to me what the full intention is? 1. protect clients from each other 2. protect clients from the Internet 3. protect the Internet from the clients Perhaps all 3 are appropriate. Regarding controlling wireless access - if this isn't done at layer 2 you have no way to protect the wireless machines from each other. That means that mechanisms such as vpns are not a full solution. For this high school, if you want to keep the hoboes off the network, probably wep is a decent tool. (Is wep breakable? Yes. Is wep useless? No. I would call it useless if someone with a standard machine and software could access your net within minutes of being within radio contact - they can't do it at all with normal software, and even if they have the special purpose software it takes hours or days to break wep/128.) One worthwhile objective should be to minimize what I call "client-side dependencies". In other words, avoid requiring special software on the users' machines just so that they can use your network. I think that rules out things like CTA. I prefer to handle network security as much as possible from the side of the infrastructure (filtering, scanning, etc.). A network IDS/IPS appears to provide a pretty good answer here. If you simply want to detect (and perhaps take special action) base on malicious traffic, an IDS should do the job. The action could be simply to alert the network admin (and let them deal with it manually), or it might be to knock the user off the network (which might be going to far in this school environment). An IPS could block the malicious traffic, but allow other traffic from the same machine. It has the added difficulty that it must be placed in-line with the traffic path. But if that can be accomplished, it is probably the simplest way to keep most bad stuff from spreading on your net. Tony Rall _______________________________________________ firewall-wizards mailing list firewall-wizards () honor icsalabs com http://honor.icsalabs.com/mailman/listinfo/firewall-wizards
Current thread:
- Securing a wireless network chris (Oct 28)
- Re: Securing a wireless network Claudiu Dragalina-Paraipan (Oct 29)
- Re: Securing a wireless network Mark Teicher (Oct 29)
- Re: Securing a wireless network Andras Kis-Szabo (Oct 29)
- Re: Securing a wireless network Gary Flynn (Oct 29)
- Re: Securing a wireless network Jim Seymour (Oct 29)
- Re: Securing a wireless network Kevin Sheldrake (Oct 29)
- <Possible follow-ups>
- RE: Securing a wireless network Smith, Aaron (Oct 29)
- Re: Securing a wireless network Michael H (Oct 29)
- RE: Securing a wireless network chris (Oct 29)
- Re: Securing a wireless network Tony Rall (Oct 30)
- Re: Securing a wireless network Mark D Robinson (Oct 30)
- Re: Securing a wireless network David Lang (Oct 31)
- Re: Securing a wireless network Jason Lewis (Oct 31)
- Re: Securing a wireless network Morrow (Oct 31)
- Re: Securing a wireless network Morrow (Oct 31)
- Re: Securing a wireless network Claudiu Dragalina-Paraipan (Oct 29)
