Firewall with MAC address ACL that is dynamic

bjriffel_at_ho__tmail.com
Date: 09/28/05


Date: 28 Sep 2005 09:34:35 -0700

Any input is appreciated!

We are a small college in Kansas and need a way to force our users in
the dormitories to install our McAfee VirusScan software. We won't be
able to physically install it, or put them into a domain. Here is our
plan so far.

We have created a silent install of VirusScan that runs a batch file
after completion. This batch file records the computer's MAC address
to a text file on a remote server. This server has a python script
that running frequently that can format the text file to our liking.

What we'd like is when the user first plugs in to our network and tries
to access a web site, they will get a default page (similar to what
most hotels have). This page will welcome them to our network and
provide a link to install the University supplied antivirus software.
After they approve the installation popups from their browser, they
would then have antivirus silently installed in the background. Their
computer would then automatically restart (via the batch file after
installation).

Now that their MAC address is in the text file on our server, we need
to allow them external network access. I've spoke with several people
about how to do this, but I'd really like more advice from others.

Right now our network looks like this:

4 T1's providing internet access to the "student network"
1 Tasman 1400 router (which is also the CSU for the T1's I think)
1 Cisco PIX 506E
Several Cisco 2900 series switches providing the network infrastructure
and a Windows 2000 DHCP server (which could also be a IIS web server)

We are prepared to build a new box to act as a proxy, firewall, or
router, which ever is needed. I'm not picky as to whether it is Linux
or Widnows.

We have a limited budget (almost $0).

If we can somehow get the PIX or tasman to redirect all trafic not
comming from MACs on our list to the web server with the download link,
then allow all traffic that IS on the MAC list, that would be perfect.
We just don't know how to set up a ACL or something that checks an
external list.



Relevant Pages

  • Re: Time clock on SBS 2003
    ... give your laptop an ip one number higher than the time clock. ... If the device was on the network and it was getting an ip using the ... guess that I would have to find the device in the server first to make it ... In the end we had to install the user interface on the server and RDP ...
    (microsoft.public.windows.server.sbs)
  • Re: Problem adding a second Domain Controller windows 2008
    ... MVP - Directory Services ... another server, I then changed to the server internal 100mb network ... issue, seem to me its a network card issue, now of course i don't want ... If you don't have the support tools installed, ...
    (microsoft.public.windows.server.active_directory)
  • Re: Connecting Vista to SBS2003 (cannot run nshelp.exe after kb926505)
    ... up a computer on the network as a client computer as part of the domain. ... We are able to see the server drives ... "When you are prompted to download nshelp.exe, click Run, and then ... I am trying to install Amicus attorney v over on the network. ...
    (microsoft.public.windows.server.sbs)
  • Re: need help re. office network install
    ... > and their network is a mess, the result of years of neglect. ... they have a gateway server w/ no special ... > firewall rules on it, they have a large DMZ that serves no purpose ... install anymore software on the firewall machine than is absolutely ...
    (comp.os.linux.networking)
  • Re: network slows down after SP2 install
    ... Dropping only the server NIC to 100MB/half duplex allowed the file transfers ... It is also odd that the physical network now cannot run ... machines with the SP2 install that prohibits running the program either ... I have 5 new machines, ...
    (microsoft.public.windows.server.sbs)