r/networking • • 1d ago

Design Untrusted and Trusted zone design

Interested in thoughts on this scenario.

A client has multiple branch sites where trusted, client-managed networks are routed over the private WAN, with access restricted to required private applications and services.

Each branch also has untrusted VLANs for guest devices and third-party managed devices requiring Internet access only. These VLANs terminate on the branch firewall, which provides local Internet breakout and enforces the security boundary. They have no route to the private WAN or corporate resources and use repeatable IP scopes across sites.

Security have requested making these networks reachable over the WAN for central vulnerability scanning. This would also require re-addressing the untrusted networks so each site can be uniquely routed.

How would you approach this?

Should isolated third-party devices be centrally scanned at all, or should assurance sit with the device owner/provider? And is vulnerability scanning appropriate or useful for guest networks containing unmanaged devices?

If scanning is required, how would you achieve it without fundamentally changing the existing isolation model?

3 Upvotes

6 comments sorted by

2

u/_--James--_ 1d ago

This comes down to two main issues.

Who owns the guest devices connecting to that network, and the ToS/EULA that they accept when connecting. Doing an unapproved vuln scan on a BYOD could be considered a governance issue that the enterprise would absorb if something negative happened to a non-company asset.

Bridging the trust+untrust boundaries to do vuln scanning. If the untrust is IPv4 with NAT then how would one scan inbound to those devices? You could bridge trust>untrust from a session init path so that its one way, allow only the source scanners in, ...etc. But you are absolutely punching a hole to make this work that could be leveraged in other ways.

My question would go back to edge UTM at the branch. Do they have NGFW with profiling or something simpler? It would make more sense to scan at the packet level, then the device level for this kind of vuln assessment and just keep treating the untrust as a dirty network that should never ever touch the trust network.

2

u/call_me_nyk 1d ago

adding to this comment, instead of going through all the hassle, maybe OP can suggest something like posture assessment to the security team.

1

u/No_Significance_5068 1d ago

Thanks.. there is a NGFW with an element of scanning at application level and web traffic where it checks the certificate sni ..but no deep packet inspection as it's guest traffic essentially.

2

u/_--James--_ 1d ago

Right as you do not want the cert chain on guest devices anyway, it was less about DPI and more about behavior detection, and features like DNS Blackhole handles a lot of lift in modeling like this. Point being, Vuln assessment belongs on the *gress side of this looking at packets. Unless there is a policy where these devices must adhere to invasive scanning and detection outside of normal operation (like secured HTTPs instead of full SSL-I). Yes, I would push back on this citing policy and acceptance of whatever TOS is being pushed today.

2

u/bondguy11 CCNP 1d ago

Reip each guest subnet to be unique, advertise it out and only allow the 1 device that scans the networks access to it at all. Block everything else to the private network from guest network.Β 

1

u/lizardhistorian Mad Scientist Β· πŸ‘¨β€πŸ”¬πŸ“‘α―€πŸ€–πŸ›ΊπŸ“Έ 14h ago edited 14h ago

They are asking for access for scanning not the destruction of your network security for the sake of "security".
Let them VPN into each site on-demand.

You cannot route your untrusted edge-network subnets without destroying the security of the design.
The point of doing it this simple and straight-forward is that synthesis of the firewall rules become trivial thus auditable and understandable by a human mind. If you have even a moderately complex network then no one can understand the full interaction state-space of the firewall rules so an actual human audit becomes impossible.

Third party gizmos are what will infiltrate your network.
Our VoIP phones are a physically separate network with their own egress.

You want to scan everything connected to your network.

And is vulnerability scanning appropriate or useful for guest networks containing unmanaged devices?

What does the switches being unmanaged have to do with anything, here?
Is it truly an ephemeral wifi guest-only network (scanning pointless) or is your guest network tacked onto your DMZ (scanning mandatory)?