<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: BYOD Devices straight to internet in HPE Aruba Networking &amp; ProVision-based</title>
    <link>https://community.hpe.com/t5/hpe-aruba-networking-provision/byod-devices-straight-to-internet/m-p/6432584#M5877</link>
    <description>&lt;P&gt;Ideally BYOD devices should be in an isolated VLAN with highly limited visability of internal resources.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Question:&lt;/P&gt;&lt;P&gt;Are the students in the same VLAN as your internal systems?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Pete&lt;/P&gt;</description>
    <pubDate>Mon, 31 Mar 2014 21:47:51 GMT</pubDate>
    <dc:creator>Pete W</dc:creator>
    <dc:date>2014-03-31T21:47:51Z</dc:date>
    <item>
      <title>BYOD Devices straight to internet</title>
      <link>https://community.hpe.com/t5/hpe-aruba-networking-provision/byod-devices-straight-to-internet/m-p/6427778#M5860</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have some 2610 and 2626 switches that are used in boarding houses, the students plug in their BYOD's such as laptops etc and connect to the internet via a proxy that prompts them for a username and password.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The problem is the users are on the network regardless of connecting to the internet.&amp;nbsp; We lock them down a bit by restricting MAC addresses but how can we lock them down so they can only access the internet via the proxy?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Would I have to create a vlan that only routes to the switch that has the proxy?&amp;nbsp; If so how to I stop vlan hopping between switches?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Sorry I'm a complete noob to switching, I'm trying but not great.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;P.S. This thread has been moved from&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;Switches, Hubs, Modems (Legacy ITRC forum) to ProCurve / ProVision-Based&lt;/SPAN&gt;&lt;SPAN&gt;. -HP Forum Moderator&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 31 Mar 2014 02:28:46 GMT</pubDate>
      <guid>https://community.hpe.com/t5/hpe-aruba-networking-provision/byod-devices-straight-to-internet/m-p/6427778#M5860</guid>
      <dc:creator>robbyde</dc:creator>
      <dc:date>2014-03-31T02:28:46Z</dc:date>
    </item>
    <item>
      <title>Re: BYOD Devices straight to internet</title>
      <link>https://community.hpe.com/t5/hpe-aruba-networking-provision/byod-devices-straight-to-internet/m-p/6428018#M5861</link>
      <description>&lt;P&gt;Is the problem that students can access the Internet without using the proxy?&lt;/P&gt;&lt;P&gt;Or is the issue that students can access internal resources that they shouldn't be able to?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Pete&lt;/P&gt;</description>
      <pubDate>Thu, 27 Mar 2014 20:34:11 GMT</pubDate>
      <guid>https://community.hpe.com/t5/hpe-aruba-networking-provision/byod-devices-straight-to-internet/m-p/6428018#M5861</guid>
      <dc:creator>Pete W</dc:creator>
      <dc:date>2014-03-27T20:34:11Z</dc:date>
    </item>
    <item>
      <title>Re: BYOD Devices straight to internet</title>
      <link>https://community.hpe.com/t5/hpe-aruba-networking-provision/byod-devices-straight-to-internet/m-p/6428506#M5862</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sorry didn’t explain very well.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The problem is the kids can access resources on the network they shouldn’t.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My main concern is although we try and get the pc's in to virus check they often are full of malware and I worry that once they're connected, they could introduce something onto the network.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 28 Mar 2014 08:15:37 GMT</pubDate>
      <guid>https://community.hpe.com/t5/hpe-aruba-networking-provision/byod-devices-straight-to-internet/m-p/6428506#M5862</guid>
      <dc:creator>robbyde</dc:creator>
      <dc:date>2014-03-28T08:15:37Z</dc:date>
    </item>
    <item>
      <title>Re: BYOD Devices straight to internet</title>
      <link>https://community.hpe.com/t5/hpe-aruba-networking-provision/byod-devices-straight-to-internet/m-p/6432584#M5877</link>
      <description>&lt;P&gt;Ideally BYOD devices should be in an isolated VLAN with highly limited visability of internal resources.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Question:&lt;/P&gt;&lt;P&gt;Are the students in the same VLAN as your internal systems?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Pete&lt;/P&gt;</description>
      <pubDate>Mon, 31 Mar 2014 21:47:51 GMT</pubDate>
      <guid>https://community.hpe.com/t5/hpe-aruba-networking-provision/byod-devices-straight-to-internet/m-p/6432584#M5877</guid>
      <dc:creator>Pete W</dc:creator>
      <dc:date>2014-03-31T21:47:51Z</dc:date>
    </item>
    <item>
      <title>Re: BYOD Devices straight to internet</title>
      <link>https://community.hpe.com/t5/hpe-aruba-networking-provision/byod-devices-straight-to-internet/m-p/6433296#M5880</link>
      <description>&lt;P&gt;No seperate vlan (everthing has a seperate vlan here, around 50 or so).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The problem is the vlans arnt bound by secuirty as far as I can tell i.e. I can access anything on the network regardless of the vlan.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So I guess what I want help with is add vlan security, i.e.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;if you are plugged into Switch A and on vlan 10 then you can only access the proxy server on port 80.&lt;/P&gt;</description>
      <pubDate>Tue, 01 Apr 2014 10:48:28 GMT</pubDate>
      <guid>https://community.hpe.com/t5/hpe-aruba-networking-provision/byod-devices-straight-to-internet/m-p/6433296#M5880</guid>
      <dc:creator>robbyde</dc:creator>
      <dc:date>2014-04-01T10:48:28Z</dc:date>
    </item>
    <item>
      <title>Re: BYOD Devices straight to internet</title>
      <link>https://community.hpe.com/t5/hpe-aruba-networking-provision/byod-devices-straight-to-internet/m-p/6435036#M5890</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sorted the issue, I've added the following ACL's:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;ip access-list extended GuestACL&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;10 permit ip 192.168.241.0 0.0.0.255 192.168.250.20 0.0.0.0&lt;BR /&gt;&lt;BR /&gt;15 permit ip 192.168.241.0 0.0.0.255 192.168.250.30 0.0.0.0&lt;BR /&gt;&lt;BR /&gt;20 permit ip 192.168.241.0 0.0.0.255 10.0.0.10 0.0.0.0&lt;BR /&gt;&lt;BR /&gt;25 permit ip 192.168.241.0 0.0.0.255 192.168.250.100 0.0.0.0&lt;BR /&gt;&lt;BR /&gt;30 permit ip 192.168.241.0 0.0.0.255 10.0.0.254 0.0.0.0&lt;BR /&gt;&lt;BR /&gt;31 permit ip 192.168.241.0 0.0.0.255 192.168.241.254 0.0.0.0&lt;BR /&gt;&lt;BR /&gt;35 permit ip 192.168.241.254 0.0.0.0 0.0.0.0 255.255.255.255&lt;BR /&gt;&lt;BR /&gt;50 deny ip 192.168.241.0 0.0.0.255 192.168.0.0 0.0.255.255&lt;BR /&gt;&lt;BR /&gt;55 deny ip 192.168.241.0 0.0.0.255 10.0.0.0 0.255.255.255&lt;BR /&gt;&lt;BR /&gt;57 deny ip 192.168.241.0 0.0.0.255 172.0.0.0 0.255.255.255&lt;BR /&gt;&lt;BR /&gt;60 permit ip 192.168.241.0 0.0.0.255 0.0.0.0 255.255.255.255&lt;BR /&gt;&lt;BR /&gt;VLAN 3241 ip access-group GuestACL in&lt;BR /&gt;&lt;BR /&gt;Show Access-List GuestACL&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So basically, the users can access the DHCP servers, firewall, proxy, their own range but nothing else.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks all&lt;/P&gt;</description>
      <pubDate>Wed, 02 Apr 2014 14:30:02 GMT</pubDate>
      <guid>https://community.hpe.com/t5/hpe-aruba-networking-provision/byod-devices-straight-to-internet/m-p/6435036#M5890</guid>
      <dc:creator>robbyde</dc:creator>
      <dc:date>2014-04-02T14:30:02Z</dc:date>
    </item>
  </channel>
</rss>

