Corporate Network Connection w/ additional Untrusted Network via E

Corporate Network Connection w/ additional Untrusted Network via E

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Corporate Network Connection w/ additional Untrusted Network via E =?Utf-8?B?cmNi?= 02-24-2006
Posted by =?Utf-8?B?cmNi?= on February 24, 2006, 8:41 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
The scenario...

A user with a laptop connected to the corporate network via a wired
connections initiates a second connection with a Verizon EVDO PDA/PCCARD to
the internet. Now the corporate network is connected to the Internet via the
laptop and the user can bypass security such as proxy servers, ect if he
wanted to. The Windows XP Firewall is off due to a Domain Policy that turns
it off due to being on the corporate network, regardless that the user has
initiated a second very untrusted connection.

Any suggestions as how to prevent this with a technical solution of product?

Posted by Roger Abell [MVP] on February 25, 2006, 2:38 am
If you were  Registered and logged in, you could reply and use other advanced thread options
First, just for clarity, in your scenario that laptop is connected to the
corp
net and the internet, but the corp net is not connected to the internet.
The laptop is not routing between them. The corp net is of course at
risk from entry of malware, or persons, via a hop off from the laptop.

The issue you raise is quite large, and AFAIK not simple to resolve
given the diverse ways an authorized device might be used to create
such a bridge. It virtually implies a very tight lockdown of the machines,
but one quite sensitive to location (ex. no modem use is on corp net,
but certainly available while travelling). I am not sure such a lockdown
is feasible today given the range of connectivity devices (ex. no usb
while on corp but ok outside?? is a bit draconian).

--
Roger Abell
Microsoft MVP (Windows Server : Security)

> The scenario...
>
> A user with a laptop connected to the corporate network via a wired
> connections initiates a second connection with a Verizon EVDO PDA/PCCARD
> to
> the internet. Now the corporate network is connected to the Internet via
> the
> laptop and the user can bypass security such as proxy servers, ect if he
> wanted to. The Windows XP Firewall is off due to a Domain Policy that
> turns
> it off due to being on the corporate network, regardless that the user has
> initiated a second very untrusted connection.
>
> Any suggestions as how to prevent this with a technical solution of
> product?



Similar ThreadsPosted
Additional Software Restriction Policies: Basic User, Untrusted, Restricted December 7, 2006, 1:10 am
Windows Security Patches w/o network connection January 19, 2006, 11:24 am
Network Connection Constantly Sending and Recieving May 11, 2007, 11:55 am
Wireless network connection not established before user login May 26, 2005, 12:28 pm
NETWORK and NETWORK SERVICE accounts April 21, 2006, 10:05 am
Authentication across untrusted domains March 29, 2006, 1:16 am
Existing untrusted Root CA May 13, 2008, 1:11 pm
RE: Network August 13, 2008, 6:12 pm
Anyone can browse my network June 29, 2005, 4:21 pm
network + testing July 7, 2005, 3:15 am

The site map in XML format XML site map

Contact Us | Privacy Policy