Solved

how to block non domain user to access internet

Posted on 2015-01-16
3
583 Views
Last Modified: 2015-01-22
hi,

We have windows server 2003 domain network with few window 7 and 8 desktop and laptop. few of our user use to bring there personal laptop in office and connect to office LAN and access the internet. we want to restrict access of internet to personal laptop.

Regards
Aditya
0
Comment
Question by:Aditya Arora
3 Comments
 
LVL 4

Expert Comment

by:Monika Bharti
Comment Utility
There are different ways of tackling this:

1. Disable unused ports (which should obviously be the first line of defense).

2. Using port security on your switch makes it at least necessary that an attacker finds out a certain MAC address and connects to a specific port, which will stop most people from plugging their home devices into the company network. In addition to this you may activate a "suspend" mode for ports: The 1st time an invalid MAC address is detected on a port it will shut down and has to be reactivated manually by an admin.

3. Radius would obviously the most fitting solution for your problem. You can configure your Windows DC as a radius authentication server and then have your switches forward the authentications request using 802.1X. The result would be that anybody trying to access the network would have to enter their username and pw used on the DC. If it is not correct they will be isolated in a separate restrictive VLAN. Disadvantage: You need hardware that supports 802.1X and have to understand VLAN concepts. I will not go into details of RADIUS here. If you are interested feel free to ask.

If you want to get more information about Radius then go through this link:

http://technet.microsoft.com/en-us/library/cc302562.aspx
0
 
LVL 53

Assisted Solution

by:McKnife
McKnife earned 250 total points
Comment Utility
Normally, companies would only permit internet access via a proxy server and at that server, you would use ACLs to permit only (certain) domain users. Don't you use a proxy server?
Domain users can be limited to certain devices through the logon workstation list, so you have all the powers.
0
 
LVL 68

Accepted Solution

by:
Qlemo earned 250 total points
Comment Utility
A proxy won't protect against well-known and Internet-enabled users, unless it requires domain authentication (instead of prompting for credentials). If you know the creds, you type them in ...

A simple "filter" is to provide a distinct DHCP IP address pool - which is only used for non-domain PCs. "Regular" PCs have to be in a different IP address range, either with a specific DHCP pool and configuring a DHCP class on each client, or manually by using DHCP reservations (based on MAC address), or with static addresses (not using DHCP).
Then the Internet gateway can filter on LAN IP address, only allowing the well-known IP address range to go out. Not very safe, though, but will stop most users.
0

Featured Post

How to run any project with ease

Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
- Combine task lists, docs, spreadsheets, and chat in one
- View and edit from mobile/offline
- Cut down on emails

Join & Write a Comment

Quality of Service (QoS) options are nearly endless when it comes to networks today. This article is merely one example of how it can be handled in a hub-n-spoke design using a 3-tier configuration.
Envision that you are chipping away at another e-business site with a team of pundit developers and designers. Everything seems, by all accounts, to be going easily.
Get a first impression of how PRTG looks and learn how it works.   This video is a short introduction to PRTG, as an initial overview or as a quick start for new PRTG users.
In this tutorial you'll learn about bandwidth monitoring with flows and packet sniffing with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're interested in additional methods for monitoring bandwidt…

762 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

8 Experts available now in Live!

Get 1:1 Help Now