Educause Security Discussion mailing list archives

Re: Ports/applications permitted for Guest Access


From: "Rowe, Ken" <kenrowe () UILLINOIS EDU>
Date: Fri, 9 Sep 2011 11:02:01 -0500

Roger,
Not something I'd post gennerally, but here is info for Univ Administration guest accounts.

The UA Guest Wireless Network allows access to the following network services only:

 *   Web Browsing (port 80/443)
 *   Secure IMAP (port 993)
 *   Secure POP (port 995)
 *   Secure SMTP via mail.uillinois.edu<http://mail.uillinois.edu> (port 25)
 *   SSH Secure Shell (port 22)


Ken Rowe, c 217.778.7693

On Sep 9, 2011, at 10:11 AM, "Roger A Safian" <r-safian () NORTHWESTERN EDU<mailto:r-safian () NORTHWESTERN EDU>> wrote:

Greetings,

We are looking at modifying and expanding our current guest access policy.  Currently guests have the same access as 
everyone else, but, they also need to have a guest ID provided to them.  This is a somewhat cumbersome process.  We 
would like relax the policy, but, at the same time, we don't want to just allow anyone to do anything on our network.

We are considering offering guest access for specific ports or applications.  Guests might not even be considered part 
of "our" network.  My question, for those of you who do have guest access is, what exactly do you allow your quests to 
do?  Our initial thought is something like web, email, vpn.  I especially am concerned that we limit P2P on the guest 
network.

Thanks.

Current thread: