Solved

Guest Wireless Network/Client VPN acess

Posted on 2013-05-30
2
637 Views
Last Modified: 2013-06-07
Hello everyone,
             Thanks to everyone in advance for your assistance.  The company I work has a wireless network that has two networks configured, one that connects to our domain and a guest network.  The guest network doesn't have access to our domain at all so it's just internet access.  The controller is an Aruba 3200XM and we have (5) AP-105's.  The other day a client came in and wanted to connect back to her office via a Cisco VPN client from the guest network.  She got a Cisco error message 412 and I think I figured out how to fix it but my question is is there a security risk with allowing clients to establish VPN connections while connected to our guest wireless network.  Thanks again for your thoughts.

Pat
0
Comment
Question by:mhmservices
2 Comments
 
LVL 21

Accepted Solution

by:
Jakob Digranes earned 500 total points
ID: 39208142
Nope not really. - given the fact that this is a guest network and you have all security rules and firewall settings correct, denying access to corporate LAN.
The only security issue is that guests can tunnel potentially unwanted traffic through the encrypted tunnel and thus bypassing your firewall.

Let's say that your guest wireless deny access to port TCP3389 (remote desktop) so when a user try to connect to a server - the traffic is stopped.
So they open a VPN connection, using their own remote gateway - so all traffic is tunneled on port 443 (SSL-VPN) or UPD500 (IKE) out from your wireless, and then goes to the RDP on TCP3389 from remote gateway.
0
 

Author Closing Comment

by:mhmservices
ID: 39228736
Thanks for sharing!
0

Featured Post

Efficient way to get backups off site to Azure

This user guide provides instructions on how to deploy and configure both a StoneFly Scale Out NAS Enterprise Cloud Drive virtual machine and Veeam Cloud Connect in the Microsoft Azure Cloud.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

The use of stolen credentials is a hot commodity this year allowing threat actors to move laterally within the network in order to avoid breach detection.
DECT technology has become a popular standard for wireless voice communication. DECT devices are not likely to be affected by other electronic devices and signals because they operate in a separate frequency-band.
This Micro Tutorial will show you how to maximize your wireless card to its maximum capability. This will be demonstrated using Intel(R) Centrino(R) Wireless-N 2230 wireless card on Windows 8 operating system.
Viewers will learn how to connect to a wireless network using the network security key. They will also learn how to access the IP address and DNS server for connections that must be done manually. After setting up a router, find the network security…

910 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

23 Experts available now in Live!

Get 1:1 Help Now