Home > Ask the Networking Experts > Wireless networking Questions & Answers > Secure network against illegal users
Ask The Networking Expert: Questions & Answers
EMAIL THIS

Secure network against illegal users

Lisa Phifer EXPERT RESPONSE FROM: Lisa Phifer

Pose a Question
Other Networking Categories
Meet all Networking Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 22 August 2006
We run NT servers with Windows 2000 workstations. We're having a problem with users illegally putting laptops on our network. We find their MAC addresses from our DHCP Manager. How can we block certain MAC addresses from accessing our network?


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
Wireless networking
How radio frequency (RF) of microwaves alter wireless signal strength
Stolen laptop recovery using remote access and wireless network SSIDs
How is wireless access point (AP) coverage affected by frequency?
Wireless AP SSID and channel configuration for a distribution network
How 802.11n wireless APs in Greenfield mode affect nearby networks
Monitoring your network to detect rogue access points (APs)
Will 802.11x wireless products be compatible with 802.11n?
How to find an SSID and identify neighboring WLANs
How to create a Wi-Fi hotspot
How to stop channel interference on 802.11x wireless access points

WLAN Security
Wireless LAN security: SonicWall joins crowded WLAN market
Stolen laptop recovery using remote access and wireless network SSIDs
Enterprise wireless LAN security: 802.11 and seamless wireless roaming
Monitoring your network to detect rogue access points (APs)
Persistent, secure connections for roaming WiMAX, 3G and 802.11x
802.11n's impact on WLAN security
Set up secure wireless networks with 802.11x, access points and bridges
How wireless network encryption affects signal strength, connectivity
New PCI compliance rules ban WEP, tighten wireless LAN security
How to avoid the WPA wireless security standard attack

Wireless Network Security
Rogue access points: Preventing, detecting and handling best practices
Securing embedded 802.11n devices
How wireless network encryption affects signal strength, connectivity
New PCI compliance rules ban WEP, tighten wireless LAN security
Best practices for securing your wireless LAN
IEEE 802.11w protects wireless LAN management frames
How can I be sure no one is hijacking or hacking my WAP?
Securing Wireless Systems -- 'Build Your Own Security Lab: A Field Guide for Network Testing,' Chapter 9
Why wireless network cards show activity when no one uses the computer
What are recent security developments for MIPv6?

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary


If you use managed Ethernet switches, you may be able to configure switch ports to bind them to known, authorized MAC addresses. This method is simple but does not scale well and can be defeated by MAC spoofing (users changing their laptop MAC address).

Your DHCP manager may support MAC Address Access Control Lists, giving out IP addresses to known, authorized MACs while denying requests from everyone else. This method is slightly more scalable -- the same ACL works no matter which switch port or AP a given laptop is using. However, it is still vulnerable to MAC spoofing.

Many new Ethernet switches and wireless APs support 802.1X Port Access Control. 802.1X is designed to overcome MAC spoofing by dynamically enabling/disabling a LAN port based on something more than MAC address. Specifically, the wired or wireless laptop will be challenged for credentials and must authenticate before network access is granted. To use 802.1X, you will need an Authentication Server that supports 802.1X, but you can probably run that on one of your NT servers and leverage your Windows workgroup and domain to authenticate LAN users. To learn about 802.1X, check out searchNetworking's Wireless Lunchtime Learning Access Control lesson.

Finally, you can also control access to your NT servers at a higher layer. For example, you could put a small business firewall between the servers and all LAN stations, requiring users to log in at the firewall to gain access to the server subnet. Or you could require domain login when workstations access individual applications and shared files/printers offered by your NT servers. Ideally, you should consider creating a layered defense by controlling access to both your LAN and your network/applications.




Search and Browse the Expert Answer Center
Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
Browse our Expert Advice



Expert networking advice and tips for IT professionals
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2000 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts