Linux Netfilter discussions
 help / color / mirror / Atom feed
From: Aleksandar Milivojevic <amilivojevic@pbl.ca>
To: Peter Marshall <peter.marshall@caris.com>
Cc: netfilter <netfilter@lists.netfilter.org>
Subject: Re: wireless security
Date: Thu, 10 Jun 2004 09:16:44 -0500	[thread overview]
Message-ID: <40C86D4C.20101@pbl.ca> (raw)
In-Reply-To: <0b5b01c44ee2$f2e7cef0$49caa8c0@caris.priv>

Peter Marshall wrote:
> Hi guys,
> 
> I am sure someone has been faced with this problem, and I was just wondering
> what the possible solutions are.  A city wide free wireless network has just
> expanded to cover the area encompassing our building.  The provider of this
> is also the provider of our Internet (via fiber).  It was decided that it
> would be advantageous for some of our employees to be able to use this
> wireless network when we bring in clients etc.  This of course opens a large
> possibility of problems concerning crap getting onto our network (especially
> if they are connected to wireless and plugged into the network).
> 
> We have made it a policy that a personal firewall be installed on all
> firewalls, and that at no time is a wireless card to be plugged into a
> laptop while connected to our LAN.  This of course does not do much for
> internal cards ....
> 
> Is there anyway at all that I can firewall this ?  Or is there a way o
> prevent the two networks from being active at the same time .. I am at a bit
> of a loss here.

I guess that machines that will be plugged to both wired and wireless 
networks are going to be Windows boxes?  I'm affraid you can't do much 
more that you already did.  Turn off IP forwarding in each of those 
Windows boxes (so they can't route traffic into your network), and turn 
on firewall on wireless interface.  Depending on how are those Windows 
boxes managed, you should be able to make policies that will prevent 
users from changing those settings.  But still, computers with wireless 
access will be the very weak spot on your network (for example, they 
will bypass any anti-virus you might have installed centrally).  IMHO, 
from security point of view, allowing such wireless access is very bad 
idea.  I'd probably put all those clients on separate physical network 
behind firewall, and would trust that network the same as I trust Internet.

If they must have wireless access, build your own wireless network that 
you controll.  If they must use public wireless network, put a wireless 
card in the firewall and remove wireless cards from the clients.  If 
they need both, make a combination of this two.

-- 
Aleksandar Milivojevic <amilivojevic@pbl.ca>    Pollard Banknote Limited
Systems Administrator                           1499 Buffalo Place
Tel: (204) 474-2323 ext 276                     Winnipeg, MB  R3T 1L7


  parent reply	other threads:[~2004-06-10 14:16 UTC|newest]

Thread overview: 14+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2004-06-10 12:03 wireless security Peter Marshall
2004-06-10 13:28 ` Antony Stone
2004-06-10 13:48   ` Peter Marshall
2004-06-10 14:10     ` Antony Stone
2004-06-10 14:16 ` Aleksandar Milivojevic [this message]
2004-06-10 14:55 ` John A. Sullivan III
2004-06-10 18:26 ` Ranjeet Shetye
  -- strict thread matches above, loose matches on Subject: below --
2004-06-10 15:43 Hudson Delbert J Contr 61 CS/SCBN
2004-06-10 16:00 ` Antony Stone
2004-06-10 16:19   ` Peter Marshall
2004-06-10 16:41     ` Antony Stone
2004-06-10 17:39       ` John A. Sullivan III
2004-06-10 18:18         ` Peter Marshall
2004-06-10 17:36 Hudson Delbert J Contr 61 CS/SCBN

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=40C86D4C.20101@pbl.ca \
    --to=amilivojevic@pbl.ca \
    --cc=netfilter@lists.netfilter.org \
    --cc=peter.marshall@caris.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox