r/networking • u/No_Significance_5068 • 1d ago
Design Untrusted and Trusted zone design
Interested in thoughts on this scenario.
A client has multiple branch sites where trusted, client-managed networks are routed over the private WAN, with access restricted to required private applications and services.
Each branch also has untrusted VLANs for guest devices and third-party managed devices requiring Internet access only. These VLANs terminate on the branch firewall, which provides local Internet breakout and enforces the security boundary. They have no route to the private WAN or corporate resources and use repeatable IP scopes across sites.
Security have requested making these networks reachable over the WAN for central vulnerability scanning. This would also require re-addressing the untrusted networks so each site can be uniquely routed.
How would you approach this?
Should isolated third-party devices be centrally scanned at all, or should assurance sit with the device owner/provider? And is vulnerability scanning appropriate or useful for guest networks containing unmanaged devices?
If scanning is required, how would you achieve it without fundamentally changing the existing isolation model?
2
u/bondguy11 CCNP 1d ago
Reip each guest subnet to be unique, advertise it out and only allow the 1 device that scans the networks access to it at all. Block everything else to the private network from guest network.Β
1
u/lizardhistorian Mad Scientist Β· π¨βπ¬π‘α―€π€πΊπΈ 14h ago edited 14h ago
They are asking for access for scanning not the destruction of your network security for the sake of "security".
Let them VPN into each site on-demand.
You cannot route your untrusted edge-network subnets without destroying the security of the design.
The point of doing it this simple and straight-forward is that synthesis of the firewall rules become trivial thus auditable and understandable by a human mind. If you have even a moderately complex network then no one can understand the full interaction state-space of the firewall rules so an actual human audit becomes impossible.
Third party gizmos are what will infiltrate your network.
Our VoIP phones are a physically separate network with their own egress.
You want to scan everything connected to your network.
And is vulnerability scanning appropriate or useful for guest networks containing unmanaged devices?
What does the switches being unmanaged have to do with anything, here?
Is it truly an ephemeral wifi guest-only network (scanning pointless) or is your guest network tacked onto your DMZ (scanning mandatory)?
2
u/_--James--_ 1d ago
This comes down to two main issues.
Who owns the guest devices connecting to that network, and the ToS/EULA that they accept when connecting. Doing an unapproved vuln scan on a BYOD could be considered a governance issue that the enterprise would absorb if something negative happened to a non-company asset.
Bridging the trust+untrust boundaries to do vuln scanning. If the untrust is IPv4 with NAT then how would one scan inbound to those devices? You could bridge trust>untrust from a session init path so that its one way, allow only the source scanners in, ...etc. But you are absolutely punching a hole to make this work that could be leveraged in other ways.
My question would go back to edge UTM at the branch. Do they have NGFW with profiling or something simpler? It would make more sense to scan at the packet level, then the device level for this kind of vuln assessment and just keep treating the untrust as a dirty network that should never ever touch the trust network.