VLAN Hopping and NAC Bypass on a Modern Office Network

VLAN Hopping and NAC Bypass on a Modern Office Network

Plug a laptop into the network point in a meeting room and see what happens. In a well configured office it gets nothing, or a quarantine network with internet access and no route to anything internal. In a great many offices it gets a corporate address, full internal routing and a domain controller two hops away. NIST’s guidance on firewall and network policy in SP 800-41 sets out the principle: separation only counts where it is enforced at every port.

Access control that stops at the printer

Where wired network access control is deployed, exceptions are what undo it. Printers, cameras, door controllers and payment terminals often cannot do 802.1X, so they are authenticated by address instead, and an address is trivial to copy. A tester reads the label on a printer, sets that address on a laptop, unplugs the printer and connects in its place. The switch sees a familiar device, applies the profile that lets printers reach the print server and the directory, and the tester now has a position inside the network that no policy anticipated.

See also: The Trulife Distribution Lawsuit: Allegations That Raised Serious Questions About Marketing Ethics

The physical shortcuts that still work

Older tricks persist because switch configurations outlive the staff who wrote them. Dynamic trunking left enabled on an access port allows a connected device to negotiate a trunk and reach multiple VLANs at once. Voice VLAN configuration announced by the switch tells a device which tagged network the phones use, and nothing stops a laptop tagging its own traffic the same way. Unused ports left active in their default VLAN provide a foothold in any room with a floor box. None of this requires exotic equipment, just a cable and a few minutes without supervision.

READ ALSO  How Technology Secures Online Transactions

“On one job the useful finding was not technical at all. The client had immaculate access control everywhere except the meeting rooms used by visitors, because the room booking system needed a network point and somebody had patched it to the office VLAN to make the screen work. Access control is only as good as its least convenient exception.”

Configuration that holds up

Disable dynamic trunking negotiation on every access port and set them explicitly to access mode. Shut down unused ports or assign them to an isolated VLAN that reaches nothing. Where address-based authentication is unavoidable for devices that cannot do better, combine it with profiling so a device claiming to be a printer must also behave like one, and place those devices on a segment with a firewall policy in front of it. Review the exceptions list quarterly, since it grows every time somebody solves a problem quickly.

Proving it rather than assuming it

Test from the positions an attacker would actually use: a meeting room, a reception area, a warehouse floor box and a desk in a shared office. An internal network penetration test that starts with no credentials and a network cable answers the question directly, and it is a short piece of work compared with a full internal assessment. When briefing a specialist testing company, ask specifically for wired access control to be tested rather than assumed, because plenty of internal tests begin from a provided laptop that is already authorised.

Frequently asked questions about wired access control

These questions come up whenever an office network is reviewed.

Is wired access control worth the effort if you have good wireless security?

Yes, because physical access to a building is easier than most people assume and a wired port usually lands in a more trusted place than the guest wireless does.

READ ALSO  When Supermetrics Alternatives Become A Strategic Choice

Do modern switches make this obsolete?

Newer hardware defaults are better and the estate is rarely uniform. The switch in the back office is often a decade old, and it is exactly the one nobody has reviewed.

Similar Posts

Leave a Reply

Your email address will not be published. Required fields are marked *