Re: MAC Filtering Part II

From: Stuart Mackie [MCP, MSP] (newsgroups_at_--REMOVE_THIS-NO_SPAM--stu.uk.com)
Date: 01/20/05


Date: Thu, 20 Jan 2005 20:33:00 -0000

Hi. As Mike has explained, IPSec is going to be the best way for you to
resolve your problem. MAC Address filtering is very insecure and can be
overcome easily. Deployment is quite straight forward using Kerberos with
Active Directory, or Certificates which requires a few additional steps for
a Certificate Authority and deployment and certificates. When configuring
IPSec you will need to consider any network attached devices which do not
support IPSec e.g. print servers, NAS devices etc. Devices which don't
support IPSec will require some additional configuration so that they are
allowed to communicate without IPSec.

In your post you don't include any details on your network layout or what
types of security intrusions you've had so far. How are you workstations
connected to the internet i.e. server acting as a gateway, direct access to
a router as a gateway etc ? How are you controlling legitimate internet
access, e.g. are you using ISA server ?

--
Hth,
Stuart Mackie
www.stu.uk.com
"KWME" <KWME@discussions.microsoft.com> wrote in message 
news:CB068EF2-FD2E-4774-B0F4-312E813A6296@microsoft.com...
> I'll try to be more complete this time.  I'm running a network in a high
> school where teachers have computers in every classroom reserved for 
> teaching
> or administrative staff only.  Students may not use this network.  Local
> machines are running XP Pro and the server is running Server 2003.  We've 
> had
> some break-ins lately where we've seen signs that students are using the 
> LAN
> connections and their own laptops to try to either hack our system or at 
> very
> least steal internet time.  I'd like to find a way to prevent ANY such 
> access
> to the system - to keep non-approved machines from getting any access on 
> the
> LAN.  I thought that finding a way to permit only certain MAC addresses 
> would
> be a simple way to do so.  Is this possible in Server 2003?  Are there 
> better
> suggestions? 


Relevant Pages

  • Re: IPSec / domain isolation: confusing MS documents
    ... workstation, he is able to attach to server ressources again, but for our ... The user right for access this computer from the network ... will not work for computer accounts unless ipsec is being used. ... securing a domain controller. ...
    (microsoft.public.windows.server.security)
  • Re: SBS Server keeps shutting down
    ... as we have had a few power cuts recently and the server kept chugging along. ... I have no idea what IPSec is ... multiple reboot mentioned above and some other troubleshooting steps ...
    (microsoft.public.windows.server.sbs)
  • Re: Setting up IPSec on a webserver
    ... IPsec in windows 2000 has I believe two main functions: ... encrypt network traffic and deciding when to filter or block network ... Using packet filters to block certain ports on a web server can be ...
    (microsoft.public.win2000.security)
  • Re: L2TP/IPSec Verbindung läuft mit XP SP2 nicht mehr
    ... In XPSP2 the IPsec driver needs a registry setting when either the ... server or workstation are behind a NAT gateway. ... 1- Client initiates to a server that is behind the NAT ... > Peer Private Addr ...
    (microsoft.public.de.german.windowsxp.networking)
  • Re: Should I install Certificate Authority to solve these problems ?
    ... You can use IPsec with or without certs from your PKI. ... negotiations to your AD machines or those trusting the ... > In the item 1 below, the tool in use is a HP server management tool (type ... >>> Management is pushing to get Certificate Authority ...
    (microsoft.public.win2000.security)