Controls are not in place to prevent bridging, multi-homing and split tunneling

IT Guy
IT Guy used Ask the Experts™
on
All - going through a security audit and that are asking us to implement controls to  prevent bridging, multi-homing and split tunneling.

we have lots of engineers both on Macs and PC's using VirtualBox and VMWare with network bridging and NATing also, has anyone ever deal with a request like this?
Comment
Watch Question

Do more with

Expert Office
EXPERT OFFICE® is a registered trademark of EXPERTS EXCHANGE®
Andrew Hancock (VMware vExpert / EE Fellow)VMware and Virtualization Consultant
Fellow 2018
Expert of the Year 2017

Commented:
we have lots of engineers both on Macs and PC's using VirtualBox and VMWare with network bridging and NATing also, has anyone ever deal with a request like this?

The problem is that these applications, require Local Administrator rights, and only way to stop them using Network Bridging and NAT, is to move them ALL the a Corporate Platform, like Hyper-V  or VMware vSphere.

It's not easily done within the application, and when it's done breaks the application. To stop it you have to stop them using it!

Which comes down to WHY do they need VMs ? if there is a developer need migrate them to a controlled platform which can be Audited.

Which we have done.....e.g. banned VMware Workstation and Virtualbox at the desktop.
Top Expert 2014

Commented:
Does this give you an alert when you press "start" ?
https://www.myabandonware.com/game/spaceward-ho-30l/play-30l

Just trying to confirm your requirement of removing the bridging/routing/NAT function from the TCP/IP stack but maintaining endpoint connectivity at this late a stage.
Dr. KlahnPrincipal Software Engineer

Commented:
I'm with Andrew.  The easiest control is "We would like to remind everyone that the corporate network is the backbone of our operation and anything other than normal everyday use requires the approval of IT Networking.  The following in particular are prohibited: ..."

Then, having fired the warning shot, wait three weeks until everyone is thinking "toothless tiger", and terminate someone very publicly with Security marching them out the door.  (You can rent "employees" for this purpose, by the way.)  The word will get around within 15 minutes, and end of problem.

Do more with

Expert Office
Submit tech questions to Ask the Experts™ at any time to receive solutions, advice, and new ideas from leading industry professionals.

Start 7-Day Free Trial