Solved

how to block non domain user to access internet

Posted on 2015-01-16
3
650 Views
Last Modified: 2015-01-22
hi,

We have windows server 2003 domain network with few window 7 and 8 desktop and laptop. few of our user use to bring there personal laptop in office and connect to office LAN and access the internet. we want to restrict access of internet to personal laptop.

Regards
Aditya
0
Comment
Question by:Aditya Arora
3 Comments
 
LVL 4

Expert Comment

by:Monika Bharti
ID: 40554942
There are different ways of tackling this:

1. Disable unused ports (which should obviously be the first line of defense).

2. Using port security on your switch makes it at least necessary that an attacker finds out a certain MAC address and connects to a specific port, which will stop most people from plugging their home devices into the company network. In addition to this you may activate a "suspend" mode for ports: The 1st time an invalid MAC address is detected on a port it will shut down and has to be reactivated manually by an admin.

3. Radius would obviously the most fitting solution for your problem. You can configure your Windows DC as a radius authentication server and then have your switches forward the authentications request using 802.1X. The result would be that anybody trying to access the network would have to enter their username and pw used on the DC. If it is not correct they will be isolated in a separate restrictive VLAN. Disadvantage: You need hardware that supports 802.1X and have to understand VLAN concepts. I will not go into details of RADIUS here. If you are interested feel free to ask.

If you want to get more information about Radius then go through this link:

http://technet.microsoft.com/en-us/library/cc302562.aspx
0
 
LVL 54

Assisted Solution

by:McKnife
McKnife earned 250 total points
ID: 40555089
Normally, companies would only permit internet access via a proxy server and at that server, you would use ACLs to permit only (certain) domain users. Don't you use a proxy server?
Domain users can be limited to certain devices through the logon workstation list, so you have all the powers.
0
 
LVL 69

Accepted Solution

by:
Qlemo earned 250 total points
ID: 40555327
A proxy won't protect against well-known and Internet-enabled users, unless it requires domain authentication (instead of prompting for credentials). If you know the creds, you type them in ...

A simple "filter" is to provide a distinct DHCP IP address pool - which is only used for non-domain PCs. "Regular" PCs have to be in a different IP address range, either with a specific DHCP pool and configuring a DHCP class on each client, or manually by using DHCP reservations (based on MAC address), or with static addresses (not using DHCP).
Then the Internet gateway can filter on LAN IP address, only allowing the well-known IP address range to go out. Not very safe, though, but will stop most users.
0

Featured Post

Announcing the Most Valuable Experts of 2016

MVEs are more concerned with the satisfaction of those they help than with the considerable points they can earn. They are the types of people you feel privileged to call colleagues. Join us in honoring this amazing group of Experts.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
windows explorer default details view 10 98
Maintain demoted SBS2011 as stand alone server 5 37
Print to local printer - Windows 7 RDP 9 47
Wireless Authentication 3 24
Quality of Service (QoS) options are nearly endless when it comes to networks today. This article is merely one example of how it can be handled in a hub-n-spoke design using a 3-tier configuration.
Envision that you are chipping away at another e-business site with a team of pundit developers and designers. Everything seems, by all accounts, to be going easily.
Here's a very brief overview of the methods PRTG Network Monitor (https://www.paessler.com/prtg) offers for monitoring bandwidth, to help you decide which methods you´d like to investigate in more detail.  The methods are covered in more detail in o…
In this tutorial you'll learn about bandwidth monitoring with flows and packet sniffing with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're interested in additional methods for monitoring bandwidt…

726 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question