11
submitted 2 months ago* (last edited 2 months ago) by brownmustardminion@lemmy.ml to c/networking@sh.itjust.works

If you have an outdoor Ethernet port—in my case with a WiFi AP connected—how can you go about protecting your network from somebody jacking in?

Is there a way to bind that port to only an approved device? I figured a firewall rule to only allow traffic to and from the WiFi AP IP address, but would that also prevent traffic from reaching any wireless clients connected to the AP?

Edit: For more context, my router is a Ubiquiti UDM and the AP is also Unifi AP

top 10 comments
sorted by: hot top controversial new old
[-] Thade780@lemmy.world 11 points 2 months ago

MAC filtering, but if the MAC address is visible from the outside AP it's pretty much useless. Radius would help.

[-] brownmustardminion@lemmy.ml 4 points 2 months ago

Yeah since the unit is easily accessible I imagine they could just read the MAC address off the sticker and spoof it.

[-] friend_of_satan@lemmy.world 10 points 2 months ago

https://en.m.wikipedia.org/wiki/IEEE_802.1X

The standard directly addresses an attack technique called Hardware Addition where an attacker posing as a guest, customer or staff smuggles a hacking device into the building that they then plug into the network giving them full access.

[-] sugar_in_your_tea@sh.itjust.works 2 points 2 months ago

Yup, I had to implement this for a customer once, and while it was a paid, it does require authentication before getting access to the network.

[-] seang96@spgrn.com 7 points 2 months ago

You could probably do an automation with home assistant to disable the report if the device gets unplugged, notify you about it, then require to you approve / re-enable the port.

This of course would require the service to be running, but combined with MAC filtering and placing it on an untrusted VLAN that's probably the best you could do.

[-] catloaf@lemm.ee 7 points 2 months ago
[-] waspentalive@lemmy.one 3 points 2 months ago

But can't that be defeated with a $5.00 wrench? [https://xkcd.com/538/]

[-] catloaf@lemm.ee 2 points 2 months ago

If people are breaking into your stuff, don't put it outside at all.

[-] aviationeast@lemmy.world 2 points 2 months ago

Low tech and cheap, best option unless you can Mac bind on your switch natively.

[-] possiblylinux127@lemmy.zip 2 points 2 months ago

Lock the Mac with port security

this post was submitted on 24 Jul 2024
11 points (100.0% liked)

networking

2783 readers
2 users here now

Community for discussing enterprise networks and the ensuing chaos that comes after inheriting or building one.

founded 1 year ago
MODERATORS