How to build a small network at work to do some private stuff unmonito

Darian_07

Honorable
Mar 4, 2013
4
0
10,510
Since I have some time available at work (not many orders since the business is going to close in several months), I would like to do some private jobs while being at the office sitting at my desk.
The problem: IT guys and my boss.

I have a laptop (given by the employer - a Lenovo) and a private laptop (Toshiba).
I would like to hide from my boss' eyes the private laptop.

That is why, initially I have used a cable from Lenovo to Toshiba, and Toshiba was in my roller box. I have been used remote access from Lenovo using UltraVNC (Toshiba the server).

Now, I would like to upgrade to a small wireless network and forget about cables (somebody has saw my cable from the desk to my roller box and I am afraid will go to my boss and explaining something that I do not desire).

Constraints:
1) Lenovo has the wireless deactivated by Windows Domain Group Policy (I guess) since I tried to enable it without success (even though I have admin priviledges on Lenovo).
2) the LAN at work is setup based on MAC (of my Lenovo), any device that has the MAC differrent than the MACs from Active Directory is not recognised, therefore it cannot be connected to workplace's LAN.
3) Internet at work goes through proxy server, so I cannot use it for private stuff because IT guys monitor internet access, but instead I would use the GSM internet on PC (Toshiba) given by my local GSM provider that has an acceptable internet connection speed.
4) IT software that I use on Lenovo is monitored by IT guys. Although I have admin rights to install any software, I am not going to install software that is not compliant with company's policies (UVNC is allowed).
5) I would like - when working for the employer - to simply plugin the UTP cable that is connecting Lenovo to the workplace LAN, but in the rest of time I can plugout that cable and have in place a wireless network to my Toshiba laptop (Toshiba I will place in my handbag that is at my feets and only a AC power will be visible, but not so visible - I can take this risk). I want to use also UVNC. That is why, I need a speedy connection (at least equal to my cable connection, i.e. 100Mbps).

Do you think this is feasible?

I have purchsed a wireless USB adapter (Belkin) that claims o speed over 100 Mbps.

I have planned to use USB wireless adapter to Lenovo, but as long as wireless is deactivated by Group Policy, I have to change my plan.

What else do I need? I though perhaps a high speed wireless router that supports MAC cloning.

So, the configuration I have in mind is: Lenovo (keeping the IP provided by the IT guys at work) connected through LAN to the high speed wireless router and further on it will go wireless to Belkin wireless adapter plugged in to USB of Toshiba.

What do you think? Is it going to work this configuration?
 
The only way you will be able to do stuff like this and not have to mess with their equipment is to use a VPN. Put your machine in your house. Then use open vpn running SSL mode to access your home network. You should be able to run though the tunnel. You could also use a public VPN server to accomplish the same thing but they may block those sites. Your traffic looks like secure http and is very hard to detect...certain firewall claim they can based on packet length..

Not sure hoe you plan to hide a router if you could not hide the cable to your laptop. If they are smart they use 802.1x to lock the mac to the port. A router cannot run eappol so even though you can clone the mac you cannot replicate the authenication.

 

Darian_07

Honorable
Mar 4, 2013
4
0
10,510
Thanks for your input, but the suggested solution I think is not feasible because the internet speed over GSM provider might not satisfy my requirements (I need to watch some video files and if they are stored at home the speed is very low; not to mention the encryption over VPN).
Mess with their equipment: I thought if I switch off their LAN (removing de cable) and plugin the wireless router (my personal network) the IT guys might not notice anything (the most thing to happen is they will notice that an employee is not connected to their LAN for whatever reasons - it does not matter to much because they are a few and my campany has hundred of employees). The router will be also hidden in my handbag, so phisically nobody will see it. If I consider again the configuration, perhaps I do not need even to change the MAC, do I?
 

Darian_07

Honorable
Mar 4, 2013
4
0
10,510
Hold on, you said a VPN through THEIR internet connection ... well ... yeah. Apologize.
I missunderstood, but I think your solution is awsome.
 

Darian_07

Honorable
Mar 4, 2013
4
0
10,510
Nope. I think it does not work (but yet have to check if it is possible or not) because they monitor any information that might quit the company. I do not want to bypass company policy, there is no info I want to get out of the company, simply I want to work on my home computer as I was at home.
 
Be careful here. No matter how you approach this, the one thing they can ALWAYS track is the destination IP of whatever you're using as a secure tunnel, whether it's a VPN service, or your home network (e.g., your own VPN server, or even SSH). So while they might not immediately know what you're doing, any monitoring they may be conducting has at least the ability to raise questions about this or that destination IP. And if these IPs are well-known, it won't take long for someone to notice. But it all hinges on just how closely things are being monitored.
 
If you don't care about being fired or not being able to list this job as a reference, simple solution would be to get a data modem and run that. Does not go though any connection except it's own, no way to have anyone trace it unless someone is actually there with you seeing what you are doing.