Home > Ask the Networking Experts > Wireless networking with Lisa Phifer Questions & Answers > Stop simultaneous connections to corporate LANs and external Wi-Fi networks
Ask The Networking Expert: Questions & Answers
EMAIL THIS

Stop simultaneous connections to corporate LANs and external Wi-Fi networks

Lisa Phifer EXPERT RESPONSE FROM: Lisa Phifer

Pose a Question
Other Networking Categories
Meet all Networking Experts
Become an Expert for this site


Wireless networks news, advice and technical information
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


>
QUESTION POSED ON: 19 July 2007

How can we stop employees from connecting simultaneously to our corporate LAN and an external Wi-Fi network?


>
EXPERT RESPONSE

Simultaneous connection to internal and external networks can present a security risk – this has long been a known VPN risk and is why many companies do not use what are called "split tunnels." When users connected to a corporate Ethernet initiate a Wi-Fi association to a neighbor's AP or a metro-area network, they expose the company network to outside threats. But preventing this from happening is not as easy as you might think.

Users could of course disable their own Ethernet connection before launching Wi-Fi, but many users cannot be bothered or forget to do this. So the real question is how can a company automatically disable Wi-Fi whenever Ethernet is active?

  1. Some IT-administered Wi-Fi connection managers have this type of policy option. For example, Juniper's Odyssey Access Client includes a wireless suppression option that uses a wireless connection only when no wired connection is present.
  2. Some host-resident Wireless IPS programs can detect and automatically prevent risky situations, including simultaneous connection to more than one network.
  3. Some distributed Enterprise Wireless IPS products have the ability to enforce policies that block Wi-Fi connections which pose a threat. This kind of prevention can stop a user from staying connected to any unauthorized Wi-Fi network while at the office, independent of other connection(s) that users may have.

Another less effective option is to use conventional desktop management tools to manipulate the routing metrics for Wi-Fi connections so that Wi-Fi will never be preferred over Ethernet when both connections are active. This is less effective because it does not actually stop any traffic from being sent over Wi-Fi -- for example, traffic destined for other users on the same metro-area Wi-Fi network will still leak out.


Sound Off! -   Be the first to post a message to Sound Off!


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


RELATED CONTENT
Wireless networking with Lisa Phifer
Buying your own WAPs vs. Internet service provider's wireless routers
What is 802.11n Greenfield mode used for?
Is my firewall setting preventing wireless network guest access?
Can you create a persistent wireless connection to a wired LAN?
Wireless troubleshooting: AP not reestablishing association after loss of connectivity
What can we expect in an 802.11n Wireless LAN standard implementation?
Can 802.11 protocols be used with GPRS connectivity?
Next generation wireless local area networks'(WLANs) important features
My wireless laptop connectivity disconnected once I downgraded my OS
How to debug poor WLAN performance

Wireless Network Security
Wireless LANs -- 'CCNA Official Exam Certification Library, Third Edition,' Chapter 11
Book of Wireless author on wireless advantages and issues
Buying your own WAPs vs. Internet service provider's wireless routers
Aruba Networks unveils wireless intrusion prevention enhancements, other security upgrades, at Interop
Is my firewall setting preventing wireless network guest access?
Wireless hot spot security -- podcast
Wireless troubleshooting: AP not reestablishing association after loss of connectivity
Wireless security protocols -- How WPA and WPA2 work
Wireless security -- How WEP encryption works
Will WPA2-PSK keep wireless networks safe from war drivers?

Wireless Security
Buying your own WAPs vs. Internet service provider's wireless routers
Aruba Networks unveils wireless intrusion prevention enhancements, other security upgrades, at Interop
Is my firewall setting preventing wireless network guest access?
Wireless hot spot security -- podcast
Wireless security protocols -- How WPA and WPA2 work
Wireless security -- How WEP encryption works
Will WPA2-PSK keep wireless networks safe from war drivers?
How to know if you're connecting to fake or real access points (APs)
Wireless network security made easy - from The Book of PF
Will 802.11n WAPs we purchase today be compatible with NAC?

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



Search and Browse the Expert Answer Center
Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
Browse our Expert Advice

HomeNewsTopicsITKnowledge ExchangeTipsAsk the ExpertsWebcastsWhite PapersNetworking Product Trials
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2000 - 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts