Home > Ask the Networking Experts > Wireless networking Questions & Answers > Stop simultaneous connections to corporate LANs and external Wi-Fi networks
Ask The Networking Expert: Questions & Answers
EMAIL THIS

Stop simultaneous connections to corporate LANs and external Wi-Fi networks

Lisa Phifer EXPERT RESPONSE FROM: Lisa Phifer

Pose a Question
Other Networking Categories
Meet all Networking Experts
Become an Expert for this site


Wireless networks news, advice and technical information
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


>
QUESTION POSED ON: 19 July 2007

How can we stop employees from connecting simultaneously to our corporate LAN and an external Wi-Fi network?


>

Simultaneous connection to internal and external networks can present a security risk – this has long been a known VPN risk and is why many companies do not use what are called "split tunnels." When users connected to a corporate Ethernet initiate a Wi-Fi association to a neighbor's AP or a metro-area network, they expose the company network to outside threats. But preventing this from happening is not as easy as you might think.

Users could of course disable their own Ethernet connection before launching Wi-Fi, but many users cannot be bothered or forget to do this. So the real question is how can a company automatically disable Wi-Fi whenever Ethernet is active?

  1. Some IT-administered Wi-Fi connection managers have this type of policy option. For example, Juniper's Odyssey Access Client includes a wireless suppression option that uses a wireless connection only when no wired connection is present.
  2. Some host-resident Wireless IPS programs can detect and automatically prevent risky situations, including simultaneous connection to more than one network.
  3. Some distributed Enterprise Wireless IPS products have the ability to enforce policies that block Wi-Fi connections which pose a threat. This kind of prevention can stop a user from staying connected to any unauthorized Wi-Fi network while at the office, independent of other connection(s) that users may have.

Another less effective option is to use conventional desktop management tools to manipulate the routing metrics for Wi-Fi connections so that Wi-Fi will never be preferred over Ethernet when both connections are active. This is less effective because it does not actually stop any traffic from being sent over Wi-Fi -- for example, traffic destined for other users on the same metro-area Wi-Fi network will still leak out.


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google



RELATED CONTENT
Wireless networking
Why is my network adapter not working after a Vista Business upgrade?
How many wireless base stations can connect to 802.11g access points?
APs drop connection in WLAN configured as a wireless mesh network
How does Wi-Fi ad-hoc mode react when 802.11n and legacy peers are present?
Can wireless adapters operate as client access points to make SoftAPs?
Will using a VPN protect me against fake wireless hotspots?
WLAN QoS and SLA monitoring with 7/24 Wireless Quality Assurance costs
How can I hide my WLAN's SSID in an Aruba AP-61?
How radio frequency (RF) of microwaves alter wireless signal strength
Stolen laptop recovery using remote access and wireless network SSIDs

WLAN Security
Where can I find a wire driver that unblocks recognized passwords?
Will using a VPN protect me against fake wireless hotspots?
Fluke gets WLAN design, management, security cred with AirMagnet
Is WPA2 secure enough for a commercial business wireless network?
Health center cut cost securing wireless network edge with Aerohive
Wi-Fi RTLS for WLAN management, location-based security, asset tracking
Wireless LAN performance management and security standards beefed up
How can I hide my WLAN's SSID in an Aruba AP-61?
Wireless LAN security: SonicWall joins crowded WLAN market
Stolen laptop recovery using remote access and wireless network SSIDs

Wireless Network Security
How to lock wireless routers
Rogue access points: Preventing, detecting and handling best practices
Securing embedded 802.11n devices
How wireless network encryption affects signal strength, connectivity
New PCI compliance rules ban WEP, tighten wireless LAN security
Best practices for securing your wireless LAN
IEEE 802.11w protects wireless LAN management frames
How can I be sure no one is hijacking or hacking my WAP?
Build Your Own Security Lab: Securing Wireless Systems
Why wireless network cards show activity when no one uses the computer

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



Search and Browse the Expert Answer Center
Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
Browse our Expert Advice



Expert networking advice and tips for IT professionals
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2000 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts