We have a private network with hard wired jacks throughout the building along with some wireless access with WPA protection. The network is based on 2003 and the 10/100/1000 Switches do not have mac address filtering. The firewall between the internet and the private network is a netscreen 5gt. This unit has the ability to create a separate zone on one of it’s other ports.
Now I know I can create a simple public access point by creating a public zone on the netscreen and connecting a switch with a couple of wireless access points for public access. This keeps folks off of our private network and all is well. HOWEVER anyone could just plug their computer into any one of our hard wired network jacks and get a DHCP assigned to them from the 2003 server and potential caused problems on our network.
What would you recommnend putting in place to protect our 2003 server(s) and our clients from folks that may just plug their computer into a network jack??? We obviously have antivirus tools and the such in place, but I would like to completely deny any sort of network access from these units.
This is a church location so the network jacks are easily accessible throughout the building so I cannot physically block public access.
Thanks.