Software to disable 3G cards while connected to corp LAN

LeviathanSA

New Member
Joined
Jun 8, 2005
Messages
8
Reaction score
0
Hi,

I work for a large corporate in South Africa, and we have a number of users who connect to the LAN while they are still connected to the 3G network. Obviously, this is a bad thing as far as security etc is concerned. Having the best firewall in the world is useless with 100 other little open windows all over the place. Is there any way to disable these devices while connected to the LAN? I have looked through these forums and can't find anybody else mentioning this issue. Surely every company in SA and the world has this problem yet there is very little to no info or solutions to it. I know user education etc must be done, and we have done it, but we can't enforce it, which is what I need.

Any help would be highy appreciated.

Thanks

D
 
Well, if you have AD, like you said you have... :D
Then applying a group-wide computer policy can be applied that will disable anything from USB ports, PCMCIA slots, xtra network adapters, specific software, etc from starting up or being enabled. :p
It is possible. :cool:

Test it first though before deploying ;)
 
Thanks for the response. I haven't found a way to do this without using some sort of end point protection software like Devicelock or Safeend. They both integrate with AD, but I don't think it can be done natively, can it?
 
Just a question being one of those type of users pulling out my 3G card while on the company LAN.

Why are the people using 3G cards while they are on the LAN? Don't you guys provide internet? Do you block any site ending with .com ? Is your internet super slow?

Anyway, i would instead look at WHY people continue using their 3G cards while they are at work [at a large corporation]...i mean come on, it's EXPENSIVE and in my case, my OWN money used to do WORK.
 
Last edited:
If security is a consideration, worry about what they're climbing onto, or what's climbing onto their machine when they're not at the office (my biggest headache!).

I'm instituting VPN only access to ensure their machines are firewalled all the time.

Essentially, for the machine to access the net, they need to use a VPN connection, the VPN is able to dialout of a MTN or Vodacom connection (using openvpn for that) but only that traffic is permitted out of HSDPA link itself.

the VPN is an IP inside our network, so that I can enforce AV updates, network filtering and what the users may and may not fiddle with on the internet including stopping the d/ling games, spyware (a pretty constant problem) and their fav programs from 'friends' on the net via email/IE and instant message.

on a side note, since open VPN compresses traffic before sending, I can deliver compressed browsing to the users as the VPN link is compressed saving on B/W usage... Yipee...

D
 
diabolus said:
Just a question being one of those type of users pulling out my 3G card while on the company LAN.

Why are the people using 3G cards while they are on the LAN? Don't you guys provide internet? Do you block any site ending with .com ? Is your internet super slow?

Anyway, i would instead look at WHY people continue using their 3G cards while they are at work [at a large corporation]...i mean come on, it's EXPENSIVE and in my case, my OWN money used to do WORK.
You will never get to the bottom of this investigation as to WHY...

Some do it deliberately, some do it due to ignorance and then there might still be left that cannot be classified under any of these.

a lot can be said for end-users
 
You will never get to the bottom of this investigation as to WHY...

Some do it deliberately, some do it due to ignorance and then there might still be left that cannot be classified under any of these.

a lot can be said for end-users

Well i know why I do it. Our company's internet just plain suck, i can't even google properly. They don't block stuff, it's just either down or dead slow. Why it's slow, probably related to people downloading movies or something, but
now THAT can be controlled though [give people accounts with caps or whatever] . I mean at university, they created proxy accounts where you had to log in and you got say 300MB a month "free", the rest you start paying. Immediately people started using internet sparingly, they rather download something once, share it on the LAN than everyone downloading it a zillion times etc etc.

As for the paying, that is something that can be different, just somehow controlling the user's bandwidth usage [if that is the cause of poor internet] is probably a better start than disabling everyon'es USB ports.

But yea, i know people use it because they feel paranoid the company is recording every word they send out through their servers. Or simply the blocking of MSN is enough to get someone to whip out his own modem.
 
Last edited:
diabolus said:
Well i know why I do it. Our company's internet just plain suck, i can't even google properly. They don't block stuff, it's just either down or dead slow. Why it's slow, probably related to people downloading movies or something, but
now THAT can be controlled though [give people accounts with caps or whatever] . I mean at university, they created proxy accounts where you had to log in and you got say 300MB a month "free", the rest you start paying. Immediately people started using internet sparingly, they rather download something once, share it on the LAN than everyone downloading it a zillion times etc etc.

As for the paying, that is something that can be different, just somehow controlling the user's bandwidth usage [if that is the cause of poor internet] is probably a better start than disabling everyon'es USB ports.

But yea, i know people use it because they feel paranoid the company is recording every word they send out through their servers. Or simply the blocking of MSN is enough to get someone to whip out his own modem.
Doesn't sound like you have good people looking after either your network or internet connectivity.
Fact is a company is there to make money, and allowing people to download all kinds of garbage form the Internet, over a company line, is a certain way of getting a high internet bill, and possibly impacting on productivity and business continuity.
The only way to prevent this is by allowing only work-related materials. It is why you work there, after all, isn't it, to do work.
Allowing certain people amounts of bandwidth, is not good IT governance. It will come back to byte you. :D
Not to mention the legal issues you can run into with people downloading music / movies onto the corporate LAN.

There should be proper rules for internet usage in place though, especially if your work requires you to be permantenly 'online'.

As for your last comment, it is the company's right to protect their intellectual property, which is a clause in the most standard of employment contracts these days. Corporate and IT governance come into play here.
Enron anyone? :p

It's statements like these that supply me with work on a daily basis ;)
 
For anyone else with this issue, (and I'm sure there must be loads!) I am having a meeting with the Safend SA distributer next week. In September they are releasing as product specifically for blocking 3G etc while connected to the LAN. I'll post here if it works.
 
lilDeath said:
Well, if you have AD, like you said you have... :D
Then applying a group-wide computer policy can be applied that will disable anything from USB ports, PCMCIA slots, xtra network adapters, specific software, etc from starting up or being enabled. :p
It is possible. :cool:

Test it first though before deploying ;)

I agree. I'm not an expert in AD, so I could be wrong. But I have definitely seen this type of policy implemented at clients. There are some assumptions though. Like you're not allowing anyone onto your LAN unless they're authenticated by AD etc. etc.
 
Top
Sign up to the MyBroadband newsletter
X