Solved

Guest Wireless Network/Client VPN acess

Posted on 2013-05-30
2
640 Views
Last Modified: 2013-06-07
Hello everyone,
             Thanks to everyone in advance for your assistance.  The company I work has a wireless network that has two networks configured, one that connects to our domain and a guest network.  The guest network doesn't have access to our domain at all so it's just internet access.  The controller is an Aruba 3200XM and we have (5) AP-105's.  The other day a client came in and wanted to connect back to her office via a Cisco VPN client from the guest network.  She got a Cisco error message 412 and I think I figured out how to fix it but my question is is there a security risk with allowing clients to establish VPN connections while connected to our guest wireless network.  Thanks again for your thoughts.

Pat
0
Comment
Question by:mhmservices
2 Comments
 
LVL 21

Accepted Solution

by:
Jakob Digranes earned 500 total points
ID: 39208142
Nope not really. - given the fact that this is a guest network and you have all security rules and firewall settings correct, denying access to corporate LAN.
The only security issue is that guests can tunnel potentially unwanted traffic through the encrypted tunnel and thus bypassing your firewall.

Let's say that your guest wireless deny access to port TCP3389 (remote desktop) so when a user try to connect to a server - the traffic is stopped.
So they open a VPN connection, using their own remote gateway - so all traffic is tunneled on port 443 (SSL-VPN) or UPD500 (IKE) out from your wireless, and then goes to the RDP on TCP3389 from remote gateway.
0
 

Author Closing Comment

by:mhmservices
ID: 39228736
Thanks for sharing!
0

Featured Post

Ransomware-A Revenue Bonanza for Service Providers

Ransomware – malware that gets on your customers’ computers, encrypts their data, and extorts a hefty ransom for the decryption keys – is a surging new threat.  The purpose of this eBook is to educate the reader about ransomware attacks.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Wifi install - small London office 9 121
PEAP with MSChap-v2 12 47
Web Fraud scenarios to PoC F5  web fraud prevention 7 38
Review of a VPN cert policy 4 28
Need WiFi? Often, there are perfectly good networks that don't have WiFi capability - and there's a need to add it.  - Perhaps you have an Ethernet port into a network but no WiFi nearby. - Perhaps you have a powerline extender and no WiFi at the…
DECT technology has become a popular standard for wireless voice communication. DECT devices are not likely to be affected by other electronic devices and signals because they operate in a separate frequency-band.
This Micro Tutorial will show you how to maximize your wireless card to its maximum capability. This will be demonstrated using Intel(R) Centrino(R) Wireless-N 2230 wireless card on Windows 8 operating system.
Viewers will learn how to connect to a wireless network using the network security key. They will also learn how to access the IP address and DNS server for connections that must be done manually. After setting up a router, find the network security…

770 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question