@dafyre said:
What I don't understand is why anyone with any IT knowledge in a business setting would treat their network as trusted? I don't even do this with my ZT netowork, and I manually authorized every device on there (granted it's only 10 so far, lol).
It is far too easy to bring in a personal device that may or may not be infected with a polymorphic bug / worm / trojan / crypto / other bad things and plug it in or connect it to the network at your business -- even if you are doing 802.11x or some other type of LAN security.
I generally keep things like the Windows Firewall and FirewallD enabled on my devices, and only punch holes in them for services that I want available on my lan or public network. This is also true of my ZT subnet as well. Why take the risk that one device could get a bug and easily share it with the rest of the systems on my ZT Subnet or LAN?
Yeah this is one of the worst parts of my network. I do monitor the LAN and run Wireshark every day but it's not great. My company will not purchase anything. I got them to buy ten raspberry pi's simply because they are cheap. I use them for all sorts of things. That's all I can really hope for (which isn't much)