cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
547
Views
9
Helpful
7
Replies

CSA 5.2.0.225 and Wireless

kerraj2004
Level 1
Level 1

Does anyone know if it is possible to stop users from connecting to wireless networks while connected from the ethernet adapter? I did create a policy and used the Rule Module included in CSA (Prevent Wireless if Ethernet Active) and it allows me to connect to wireless networks.

Any info would be greatly appreciated.

1 Accepted Solution

Accepted Solutions

I think they create them so they are there if needed and you don't have to create them from scratch.

You could associate the existing rule module with a new Wireless Connection policy and attach that to your groups.

Whether you clone and modify copies or modify the original is a personal preference.

It should work either way and there are folks who prefer one over the other for various reasons.

Tom

View solution in original post

7 Replies 7

tsteger1
Level 8
Level 8

I did in 5.2.210.

I used the Ethernet active with DNS suffix matching System State and the $Wi-fi [V5.2 r210].

It worked as expected.

Tom

Bradley Spencer
Level 1
Level 1

Yea the module still allows you to connect to the wireless network but does not allow traffic.

You could always look at blocking DHCP on wireless so you don't get an address.

Also, if you are using a managment application for the wireless interface you could always try blocking that from executing so the wireless connection does not establish. That is in theory but it should work.

So being that the rule module is in place without a policy, is it best that the rule be copied and then used. I guess i really dont understand why they have rule modules but do not associate it with a policy out of the box.

Thanks!

I think they create them so they are there if needed and you don't have to create them from scratch.

You could associate the existing rule module with a new Wireless Connection policy and attach that to your groups.

Whether you clone and modify copies or modify the original is a personal preference.

It should work either way and there are folks who prefer one over the other for various reasons.

Tom

The Network Access Control rule is not performing the way i'd like. I would like for the rule with a system state of "Ethernet" is active to disable the wireless adapter from getting an IP address and or connecting to the AP. I dont want the brige my protected network with an unprotected one. I added the network service UDP/TCP along with the 192 ip range but has not corrected my issue.

Thanks,

As Bradley mentioned, it does connect and get an address but does not allow traffic.

It wasn't designed to disable the adapter or DHCP, just deny access through the adapter.

There may be other things you can do to lock it down further but I think it is doing what you need it to.

Tom

Has anyone managed to get the CSA to disable the WLAN adapter if an ethernet connection is detected?

Although the CSA is ensuring that wired/wireless networks aren't bridged, it would be ideal if it could disable the adapter before it connected to a WLAN network instead of simply blocking traffic.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: