directconnect & um’s network access control

31
DirectConnect & UM’s Network Access Control University of Montana - Missoula Adam Ormesher & Chase Maier

Upload: jillian-foley

Post on 31-Dec-2015

33 views

Category:

Documents


0 download

DESCRIPTION

University of Montana - Missoula Adam Ormesher & Chase Maier. DirectConnect & UM’s Network Access Control. Background Information. We provide internet to about 3000 residents All ten dorms are currently wired-only connections NAT – Not enough forward facing IPs - PowerPoint PPT Presentation

TRANSCRIPT

Page 1: DirectConnect & UM’s Network Access Control

DirectConnect & UM’s Network

Access Control

University of Montana - Missoula

Adam Ormesher & Chase Maier

Page 2: DirectConnect & UM’s Network Access Control

Background Information

We provide internet to about 3000 residents

All ten dorms are currently wired-only connections

NAT – Not enough forward facing IPs Outside connection managed by Central

IT – Not us

Page 3: DirectConnect & UM’s Network Access Control

IP Address Pools Each residence hall has two designated

pools of IP addresses for use by clients.

“dirty pool” not registered or banned○ 10.247.__.__

“clean pool” devices which have been registered and are able to access the Internet and network resources.○ 10.248.__.__

Page 4: DirectConnect & UM’s Network Access Control

Network Level Restrictions Each switch blocks outbound DHCP

Offers on all switch interfaces.A single exception is necessary allowing our

approved DHCP server to provide devices with leases.

This helps alleviate problems caused by students plugging in routers backwards which compete with our DHCP server.

Page 5: DirectConnect & UM’s Network Access Control

Network Level Restrictions

Page 6: DirectConnect & UM’s Network Access Control

Network Level Restrictions Rouge DHCP Example

Student Router Student Router

Page 7: DirectConnect & UM’s Network Access Control

DCOHome - Uses

Custom web application containing:Residence Halls Switch Port ControlResidential DHCP Backend Data StoreStudent Housing Records

Page 8: DirectConnect & UM’s Network Access Control

DCOHome – Student Info

Student Personal InformationStudent ID, NetID, Name, Email, Phone #

Housing InformationDorm & Room #

The above information is updated daily from Banner for students living in our residence halls.

Page 9: DirectConnect & UM’s Network Access Control

DCOHome – Registration

Each device that is connected to the network is given a DHCP lease based on MAC Address.

Each device is assigned to an existing student.

Game consoles are manually registered by our employees.

Page 10: DirectConnect & UM’s Network Access Control

DCOHome – Ban Methods Using the ban system we are able to:

Ban specific MAC Addresses

Ban all devices registered to a student.

Banned machines are returned to the “dirty pool.”

Page 11: DirectConnect & UM’s Network Access Control

DCOHome – Ban Reasons Student conduct violations

DMCA violations

Network Impacting Infections

Malfunctioning hardware

Unauthorized hardware

Page 12: DirectConnect & UM’s Network Access Control

DCOWeb – Overview

DCOWeb provides the following:

DHCP Server

Web Server

DNS Server

Page 13: DirectConnect & UM’s Network Access Control

DCOWeb – DHCP Server

Developed using Java by our internal programming team.

Communicates with DCOHome using XML.

Page 14: DirectConnect & UM’s Network Access Control

DCOWeb – Web Server

Contains pages with:Instructions to be followed to register.Commonly downloaded files.

○ Windows Service Packs○ .NET Installers○ Antivirus & Antimalware Utilities

Page 15: DirectConnect & UM’s Network Access Control

DCOWeb– DNS Server

Computers in the “dirty pool” are assigned DCOWeb as their DNS server.

All DNS lookups sent to DCOWeb resolve to the IP of DCOWeb (10.248.242.55).

What is IP for “www.google.com”?

10.248.242.55 (DCOWeb)

Client In Dirty Pool DCOWeb

Page 16: DirectConnect & UM’s Network Access Control

Overview

Student info

DHCP log

Port status

DHCP Server

DNS Server

Hosted Files

Client(Student machine)

DCOHome DCOWeb

Page 17: DirectConnect & UM’s Network Access Control

DCOWeb – Mac Setup

Page 18: DirectConnect & UM’s Network Access Control

DCOWeb – Windows Setup

Page 19: DirectConnect & UM’s Network Access Control
Page 20: DirectConnect & UM’s Network Access Control
Page 21: DirectConnect & UM’s Network Access Control
Page 22: DirectConnect & UM’s Network Access Control
Page 23: DirectConnect & UM’s Network Access Control
Page 24: DirectConnect & UM’s Network Access Control
Page 25: DirectConnect & UM’s Network Access Control
Page 26: DirectConnect & UM’s Network Access Control
Page 27: DirectConnect & UM’s Network Access Control
Page 28: DirectConnect & UM’s Network Access Control
Page 29: DirectConnect & UM’s Network Access Control
Page 30: DirectConnect & UM’s Network Access Control
Page 31: DirectConnect & UM’s Network Access Control

Questions?

www.resnetsymposium.org/rspm/evaluation/