Re: Dial up question

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance



On Sun, 11 Dec 2005 17:15:02 -0800, "S.Huang" <SHuang@xxxxxxxxxxxxxxxxxxxxxxxxx>
wrote:

>"Chuck" wrote:
>
>> On Thu, 8 Dec 2005 22:12:02 -0800, "S.Huang" <SHuang@xxxxxxxxxxxxxxxxxxxxxxxxx>
>> wrote:
>>
>> >Is there a way to only allow company?s laptops to connect via dial-up and
>> >restrict home PC or any other computer from making the same connection via
>> >dial-up? It?s just a security concern that if computers other than the
>> >company?s computer is connected to the corporate network.
>> >
>> >Thanks
>>
>> Your query leaves me with several questions, and makes me wonder whether you
>> need the services of a skilled security technician, to develop a Corporate
>> Security Policy, including enforcement and penalty sections.
>>
>> Which of the following scenarios (or all of them) are you worried about?
>> 1) Employee takes laptop home, dials in to the Internet, allows other computers
>> to connect to it, and shares Internet access.
>> 2) Employee takes laptop home, allows other computers to connect to it, and
>> shares resources (in / out) maybe file sharing, with non-company computers.
>> 3) Employee sets up non-company computer, as laptop is setup, and uses that
>> computer instead of laptop to connect to company resources (not Internet).
>>
>> Which of these scenarios are you afraid that your employees are sufficiently
>> technically advanced, and interested, that they would do even if instructed by
>> Corporate Security Policy, to not do?
>>
>> In other words, have you explicitly instructed your employees NOT to do these
>> things, and are they sufficiently technically skilled and untrustworthy, that
>> they are likely to do them anyway?

>User uses ethernet to connect in the office with restricted acess and Active
>Directory is used.
>
>We have security policy implemented and the main concern is user setup their
>home PC as company laptop. After all it's not that difficult to setup a dial
>up account on a PC, all they need to know is the telephone number.
>
>what I am after is the way to ensure that employees can not or make it
>harder to breach the policy by enforcing restrictions on the actual dial-in
>connection. I was thinking is it possible to setup a certificate on the
>laptop and the dial-in server checks the certificate to allow or deny access?

Do you have Active Directory? If so, put the laptops in an AD container, and
deny dialup access to any other computers.

If not, a certificate would be one way to go. If the nuisance of installing
certificates on both the server and the clients isn't too much of a bother.

--
Cheers,
Chuck, MS-MVP [Windows - Networking]
http://nitecruzr.blogspot.com/
Paranoia is not a problem, when it's a normal response from experience.
My email is AT DOT
actual address pchuck mvps org.
.



Relevant Pages

  • Re: Dial up question
    ... >restrict home PC or any other computer from making the same connection via ... Security Policy, ... Employee takes laptop home, dials in to the Internet, allows other computers ...
    (microsoft.public.windowsxp.network_web)
  • Guest Wireless Access to Internet
    ... I need to give someone access to the internet from their laptop, ... My system is set up with a broadband connection into a Draytek Vigor ... I would ideally like to restrict what can be downloaded, ... liable for any illegal activities through my Internet Connection). ...
    (microsoft.public.windows.server.sbs)
  • Re: Using 3 Screens with Laptop
    ... Right now, I can only use two screens at a time--either the laptop screen and one LCD, or both LCDs without the laptop screen. ... video connection, and split the image to fit two monitors. ... TripleHead2Go comments - VGA or DVI in, ...
    (microsoft.public.windowsxp.general)
  • Re: Unsolvable windows networking problem
    ... Is the router security set to MAC Address Filtering? ... >> Wired connection to desktop running Windows XP Home ... >> Wired and wireless connection to laptop running ... >> There are 2 servers in domain NEWHOME on transport ...
    (microsoft.public.windowsxp.general)
  • Re: 1 way remote desktop
    ... I am using the local ip of the desktop as seen on my lan ... laptop = 192.168.0.3 ... also remote access connection mgr is up. ...
    (microsoft.public.windowsxp.work_remotely)