LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 10-16-2022, 11:30 AM   #1
wh33t
Member
 
Registered: Oct 2003
Location: Canada
Posts: 922

Rep: Reputation: 61
Question Can an RJ45 port on the exterior of a building be used maliciously if DHCP is off, and MAC address filtering is on?


Here is some background on this peculiar question.

I'm researching Access Controls, and very intrigued by the idea of using 100% POE powered/connected badge readers, strikers, locks, motion sensors etc. The vibe I get from the access control community is these are probably fine to use indoors, but not on the exterior of the building as someone "could just pry open the box" and then they'd have access to an RJ45 port or ethernet cable which they could use to launch attacks.

So I've been scratching my head how to deal with this concern. My thinking was that if I turned off DHCP, and only permitted specific devices with known mac addresses (managed switch/router) to communicate and then only permitting them to communicate with the central server this particular vector would be nullified. But then I started thinking there are other ways to send attacks on ethernet that don't involve IP right? IPX/SPX, NULL, ARP, SYN? These are all different network communication protocols right?

How would you handle this situation?

Last edited by wh33t; 10-16-2022 at 11:32 AM.
 
Old 10-16-2022, 12:32 PM   #2
business_kid
LQ Guru
 
Registered: Jan 2006
Location: Ireland
Distribution: Slackware, Slarm64 & Android
Posts: 16,304

Rep: Reputation: 2324Reputation: 2324Reputation: 2324Reputation: 2324Reputation: 2324Reputation: 2324Reputation: 2324Reputation: 2324Reputation: 2324Reputation: 2324Reputation: 2324
Firstly, I'd say that you not only have to be secure, but convince less knowledgable superiors that you are.

An input is only a danger if anyone is listening to it. So if you
  1. Run ifconfig ethX down on each interface, or
  2. Physically disconnect such devices
They won't present a danger. Your worst case scenario would probably be some script kiddie with his laptop plugging in. You won't convince anyone that you're secure without enforcing one of the above in a foolproof fashion. I'd regard a live functional nic as a large security hole. Why hand someone a stick to beat you with?
 
Old 10-16-2022, 02:29 PM   #3
yvesjv
Member
 
Registered: Sep 2015
Location: Australia
Distribution: Slackware, Devuan, Freebsd
Posts: 565

Rep: Reputation: Disabled
Cool

Quote:
Originally Posted by wh33t View Post
Here is some background on this peculiar question.
How would you handle this situation?
Pretty common situation.
Use DAI and wired dot1x where users that cannot auth are blocked (or placed into a special purpose vlan).
Note that some valid devices will be so old they will not be able to do any dot1x auth.
Yet, if you have special purposes devices for BMS traffic, IP Cameras, etc perhaps create VRFs if you can.

There is also another scenario where you can go with DAI and pvlans.
Haven't done this one but it should be feasible.
 
Old 10-17-2022, 12:30 PM   #4
elgrandeperro
Member
 
Registered: Apr 2021
Posts: 415
Blog Entries: 2

Rep: Reputation: Disabled
Vlans definitely with only the devices. Then you connect them on a separate leg of a layer 2 firewall, with specific rules to only allow connections to the server. We do this for like video/av stuff and cameras as well as door locks. So the answer is don't put that network on your network, either physically or logically.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Can I install Ubuntu onto an exterior hard drive to install into another computer? oovee Linux - Newbie 6 09-10-2013 07:38 PM
Questions on DHCP Filtering via MAC address brainee28 Linux - Networking 1 02-03-2005 02:11 PM
iptables and connecting to exterior ftp from behind hardware router mdkelly Linux - Networking 1 07-14-2004 04:06 PM
laptop exterior, read this please! zetsui Linux - Laptop and Netbook 6 08-09-2003 11:30 PM
How to mount an exterior Hard Drive rdaves@earthlink.net Linux - Newbie 14 06-30-2001 02:59 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 12:50 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration