It's a decent approach, though in most cases like that an sslstrip type of attack would still fool a majority. A certificate based VPN may be the most practical client only defense.
Engineering wise this is really a problem to solve at the local LAN, employing individual vlans or other techniques to strictly segment traffic on top of encryption, or simply implementing port based network access control via 802.1x.
Engineering wise this is really a problem to solve at the local LAN, employing individual vlans or other techniques to strictly segment traffic on top of encryption, or simply implementing port based network access control via 802.1x.