Educause Security Discussion mailing list archives

Re: HEOA Question


From: Matthew Gracie <graciem () CANISIUS EDU>
Date: Mon, 31 Jan 2011 09:56:28 -0500

On 01/31/2011 09:44 AM, William Derwostyp wrote:
I need some input.

Here at USM the students are segregated to a wireless network that is
now behind a single address(NAT). This has caused a problem with
responding to RIAA notices as we cannot tie the notice to a specific
user on the network which in turn affect the compliance to the “Higher
Education Opportunity Act” (HEOA).

 

I am going to assume that there are other universities that use the NAT
process to control traffic on their perimeter and use non-routable
addresses on the internal network. Is there any tool or application I
can use that will help to tie the notices back to the person without
having to go back to public addressing?

If you're using Cisco gear on the edge of the wireless network to handle
the NATing, it might be helpful to turn on Netflow and send the flow
data to a collector. Even an open-source tool like Flowviewer would give
you better records of which client is passing what kind of traffic;
depending on the number of IPs we're talking about, that might be
sufficient to handle your HEOA demands.


-- 
Matt Gracie                         (716) 888-8378
Information Security Administrator  graciem () canisius edu
Canisius College ITS                Buffalo, NY
http://www2.canisius.edu/~graciem/graciem_public_key.gpg        


Current thread: