RE: broadband connections in hotels

From: Brad O'Brien (brad.obrien@brylade.com)
Date: 12/09/02

  • Next message: Louis Cypher: "Fwd: FW: XP admin shares"
    To: security-basics@security-focus.com
    Date: Mon, 09 Dec 2002 14:36:22 -0500 (EST)
    From: Brad O'Brien <brad.obrien@brylade.com>
    
    

    Greetings Peter,

             From what you describe, one thing that you may want to try is allow
    access to 192.168.x.x by IP only in the firewall rules as most of the webpages
    from hotels are internal sites. This has it’s obvious disadvantages, so you
    have to decide how much security you want to sacrifice in order to maintain
    flexability for the user.

             If they are external sites, then you could have the person dial-up
    with the built in 56K modem and VPN into work, thereby using the corporate
    proxy and then authenticate the password on the site in question. That should
    activate the billing for a set period of time (usually one night) and allow
    the user to then disconenct the dial-up and connect to the broadband
    connection.

             If all else fails, most of the hotels offering broadband to their
    guests would have a PC that the front desk that has an unrestricted internet
    access to that could initiate the billing on the travelers behalf.

    Hope this helps,
    Brad O'Brien
    Operations Manager
    Brylade Computer Solutions Ltd.

     

     

     

     

    -----Original Message-----
    From: Peter VE [mailto:peter.ve@pandora.be]
    Sent: December 6, 2002 5:38 PM
    To: security-basics@security-focus.com
    Subject: broadband connections in hotels

     

     

    Hi all,

     

    I have a problem that has been bothering me for quite some time now

    All of our laptops have a personal firewall.

    THis means that they can connect to the internet (in terms of getting an IP

    address and do DNS name resolution) + establish a VPN tunnel into the

    corporate network. That's it... no browsing allowed, no email reading or

    sending allowed....

    When the users wants to access the internet, he has to establish the VPN and

    use the corporate proxy server... better safe than sorry

    The users are not able to change the firewall policy nor disable the

    firewall... it's always running

    The firewall is clever enough to detect when you are on the corporate

    network (private IP + ability to resolve internal DNS names), when you are

    on the internet (non-corporate IP address, or private ip address but not

    able to resolve corporate internal DNS name), when you are using VPN and so

    on... this really works well

     

    Some hotels offer a broadband connection... but before you can access the

    internet, you need to connect to a website, and enter a passcode (so proper

    billing can be done). We are blocking all access so the user cannot access

    this website...

    This is bothering me... how can we set things up so the user can use the

    local broadband connection,

    without dynamically changing the policy,

    without allowing internet browsing access at all times..

    Also, keep in mind that not all websites are running on port 80... it could

    be a different port...

     

    Any ideas ?

     

    thanks

     

    P



    Relevant Pages

    • RE : broadband connections in hotels
      ... Objet: Re: broadband connections in hotels ... The device hosting the web page in the hotels your users are using is ... PV>All of our laptops have a personal firewall. ... PV>connect to the internet (in terms of getting an IP address and do DNS ...
      (Security-Basics)
    • Re: avast
      ... > Just did a clean installation of xp pro sp1 and download 'avast anti ... Did you firewall before connecting to the internet? ... Internet and patch with the critical updates? ... Why you should use a computer firewall.. ...
      (microsoft.public.windowsxp.general)
    • Re: XP NOT RESPONDING
      ... Did you have a firewall going before connecting to the internet? ... Microsoft has these suggestions for Protecting your computer from the ... Why you should use a computer firewall.. ... are pay - some you can only download if you are registered - but it is best ...
      (microsoft.public.windowsxp.setup_deployment)
    • Re: Guide to secure installtion of IIS 5
      ... don't forget a well-configured firewall. ... Do not put the computer onto the network or the Internet until after the ... Follow the instructions for hardening Windows and IIS at ... Install all service packs and security fixes from Microsoft and otherwise ...
      (microsoft.public.inetserver.iis.security)
    • RE: firewall
      ... You need to do a lot of reading about ipfw ... IPFW is the only firewall available to FBSD, ... rules do not function correctly on a DSL or cable internet ... @320 pass in quick on rl0 proto tcp from 63.70.155.0/24 to any port ...
      (freebsd-questions)

  • Quantcast