Re: Filtering DHCP Assignments by MAC Address

From: Justin Pryzby (justinpryzby_at_users.sf.net)
Date: 06/23/03

  • Next message: Joseph Kim - HQ: "RE: Managing Windows Event Logs"
    Date: Mon, 23 Jun 2003 11:05:55 -0700
    To: Stuart Fox <StuartF@datacom.co.nz>, focus-ms@securityfocus.com, jakefr0st@hotmail.com
    
    

    You can set up users' default gateway to reject unregistered ip
    addresses. I know of at least 2 universities that do this. The
    gateway redirects tcp:80 requests to http://start/, which is a page
    that says prompts for username,passwd, and detects mac address.

    In this case, a static IP would also fail. However, users can still
    spoof their mac address. Or rewrite the network card's EEPROM.

    But they're not supposed to know that.

    Justin

    On Mon, Jun 23, 2003 at 07:25:05PM +0000, Stuart Fox wrote:
    >
    > Assuming you do that, what's to stop someone plugging in with a static IP
    > address and getting around whatever restrictions you have in place?
    >
    > By assigning by MAC address you've just transferred your problem of keeping
    > track of IP addresses to keeping track of MAC addresses & IP addresses. You
    > might as well go back to static IP in that instance.
    >
    > Cheers
    >
    > Stu
    >
    > > -----Original Message-----
    > > From: Jake Frost [mailto:jakefr0st@hotmail.com]
    > > Sent: Friday, 20 June 2003 9:51 a.m.
    > > To: FOCUS-MS@SECURITYFOCUS.COM
    > > Subject: Filtering DHCP Assignments by MAC Address
    > >
    > >
    > > We have just converted to DHCP and would like to limit the
    > > ability of people
    > > to plug in to the network without authorization. In Win2K is
    > > it possible to
    > > limit DHCP assignments by MAC address or some other mechanism
    > > to keep rogue
    > > machines out? My server admins have been researching this
    > > but can't find a
    > > method to achieve what we want. Thanks.
    > >
    > > Jake
    > >
    > > _________________________________________________________________
    > > MSN 8 helps eliminate e-mail viruses. Get 2 months FREE*.
    > > http://join.msn.com/?page=features/virus
    > >
    > >
    > > --------------------------------------------------------------
    > > ---------------
    > > --------------------------------------------------------------
    > > ----------------
    > >
    >
    > -----------------------------------------------------------------------------
    > ------------------------------------------------------------------------------
    >

    -----------------------------------------------------------------------------
    ------------------------------------------------------------------------------


  • Next message: Joseph Kim - HQ: "RE: Managing Windows Event Logs"

    Relevant Pages

    • Re: Mac OS X at 8%
      ... using Vista as are using all versions of Mac OS put together. ... Or is it that more Windows computers are hidden behind routers than Macs ... Hiding behind routers doesn't change the stats, Edwin. ... How would they possibly know whether one copy of IE made a hundred requests, ...
      (comp.sys.mac.advocacy)
    • Re: security of IP address
      ... > the router ... ... Initial DHCP requests are broadcast frames, ... MAC is really all you have to work with initially. ...
      (comp.os.linux.networking)
    • Re: Browser stats at the BBC
      ... >> There's an interesting analysis of web browsers used to access the BBC home ... > versions of the Mac OS that people were using to request the BBC ... I established that from the requests we saw I could identify ...
      (uk.comp.sys.mac)
    • Re: Blocking a computer from a wireless router.
      ... computer that access resources requested and sent through your router, ... so I figure there must be a way to block those requests. ... 'MAC address filter'. ... computers by MAC address, or disallow listed computers. ...
      (alt.internet.wireless)
    • Re: Blocking a computer from a wireless router.
      ... so I figure there must be a way to block those requests. ... 'MAC address filter'. ... John Navas FAQ for Wi-Fi: ...
      (alt.internet.wireless)