Yeah.To each their own I guess....
I guess some of us are competent and concerned about network security and some.... aren't.
Follow along with the video below to see how to install our site as a web app on your home screen.
Note: This feature may not be available in some browsers.
Yeah.To each their own I guess....
Yeah.
I guess some of us are competent and concerned about network security and some.... aren't.
You'd probably be well advised not to make baseless assumptions about the employment of other people.Go back to maintaining mom and dads home network troll.
Good point.
OP, why do you have two public IPs? Perhaps you can eliminate this VERY easily by dropping the 2nd one?
Just use local permissions and cut the user access down. It will solve all your problems and some that you don't yet even know you have.
one of my office buildings has just 1 computer... just 1 stand alone unit and even that has the access limited using gpedit.msc
I'll add that corrective action needs to be taken with this user. I suggest implementing some IT policies and have the users agree to them immediately if you have not already done so.
Before you go internet nut swinging you have no clue what people's credentials are.
I provided a scenario based on the "domain users in the local administrators group" line that is easily repeatable and, aside from shutting from admin shares which are used by many many different applications, there's little you can do to stop it. I also provided a way around providing local administrative access (regmon/filemon and specific file access) and a better policy to apply (individual credentials on individual systems rather than "Domain Users") when faced with challenges. Many applications will also work just fine with Power User permission rather than full-blown administrative access.You should think about a full policy before saying local admins are the devil.
The answer is very simple - many auditors and security companies rely on software and many security applications scan from an external aspect without administrative credentials. Want to see something scary? Ask them to run a scan using user credentials rather than scanning against the perimeter without credentials.If our security was so bad as you insist it is, why would our SOX and EY auditors not have one word to say about security, what about the 3rd party company hired to test security against us. Assuming they all dont know what their doing because of my one line shows your ingnorance for the big picture.
See the first quote as you said it best yourself. You're making a wild assumption as well. If you would have said that about me or a number of others here you'd be sorely mistaken. Not that I'm the end-all-be-all either, there are better. You stick around in this industry long enough and you'll realzie that the truly frightening fact of the matter is that nothing is ever secure. If it can be built, it can be unbuilt.Go back to maintaining mom and dads home network troll.
Assuming they all dont know what their doing because of my one line shows your ingnorance for the big picture..
Better yet, why does he have the ability to change the IP on his workstation?
because we got a T1 they assignd us 6 IP's (4 usabel) with it. i guess i could ask them to take the others away and only give us the one? but knowing the ISP's here anything that causes work they will refuse to do and also if we ever need more IP's i am sure it would be a nightmare to get them back
^^ sweet!! just saved that!!
havent had a chance to mess with th router yet, fixing a MySQL db currently cause the last operations people didnt bother to have any type of backs-ups, or raid set ups! argh what fun!
Yeah.
I guess some of us are competent and concerned about network security and some.... aren't.
Then I would definitely just block the IP addresses- only allowing those in your DHCP range. Still not quite sure how they were even working in the first place... Might be something you look into- but fixing it now will stop it.
After testing it to make sure it works (And that the IP addresses don't work), be sure to save it to your startup config (right now (unless you did already) it is just running in RAM. As soon as power is lost- settings are forgotten).
copy run start is the command to do that.
Two things:
1) Fix your NAT settings
2) Remove this person's admin rights. No admin rights, can't set an IP.
Agree 100%.I swear, if any of the 5 admins who work for me suggested solving a network topology problem with OS-based solutions, I'd send them straight back to school.
For the last time, this is a basic network topology and basic networking security problem. It isn't a user-behavior problem. It isn't an OS administration or active directory problem. What this guy is doing should be made irrelevant and useless at the gateway/perimeter device - that is proper networking design. If you cannot understand how to implement this, for pete's sake hire a consultant who does.
I swear, if any of the 5 admins who work for me suggested solving a network topology problem with OS-based solutions, I'd send them straight back to school.
For the last time, this is a basic network topology and basic networking security problem. It isn't a user-behavior problem. It isn't an OS administration or active directory problem. What this guy is doing should be made irrelevant and useless at the gateway/perimeter device - that is proper networking design. If you cannot understand how to implement this, for pete's sake hire a consultant who does.
I swear, if any of the 5 admins who work for me suggested solving a network topology problem with OS-based solutions, I'd send them straight back to school.
For the last time, this is a basic network topology and basic networking security problem. It isn't a user-behavior problem. It isn't an OS administration or active directory problem. What this guy is doing should be made irrelevant and useless at the gateway/perimeter device - that is proper networking design. If you cannot understand how to implement this, for pete's sake hire a consultant who does.
Agree 100%.
I said a page or so ago that the OP is wholly unqualified to configure this device. A forum thread is not the place to learn truly basic network topology.
Your best bet is to simply find a basic router configuration/network design book and bury yourself in it or to simply find someone who knows what's going on.
At the very least taking that right away will put a temporary, immediate solution in place, this taking the compromised portion of the network out.
This is especially true since the OP can't get into the router and change it to fix it right now.
Then, after you have the band-aid on, you go in and fix the problem later.
Or you can let things go, and let this user run rampant on the internet doing who knows what while you wait for who knows how long to figure out how to fix it. Since this user is obviously a local admin, he can do a lot of damage quickly. And, again, obviously he knows enough to be a concern.
OP; have you thought of a proxy server, by any chance? That way you can at least still see (and filter if wanted) what this user is doing.
i was considering this aswell, we have an SBS license, installing it and using ISA as the main gateway out, basically doing what the user did with the IP, setting up the external IP on the ISA and forcing everyone to go through it.
T1--> CISCO--->ISA--> Network
this way he definetly couldnt get around the ISA or use an external IP as i would not allow it via the ISA, this would be a temp solution until i get the router properly configured.
I know compared to many i dont know jack, but that certainly doesnt mean i dont know what i am / should be doing, or need to do, is just how to do it with the cisco, CLI for some reason has always intimidated me, i didnt get into computer until win98, so DOS was never something i used much, i got spoiled with purdy GUI crap.
perhaps i am missing something
understanding basic network topology, and not knowing how to configure a specific model of router seem like 2 VERY different things to me....
how is this helping him?
how is this helping him?