RE: [Maybe Spam] Dhcp security

From: Phil Waller (phil.waller_at_wgsn.com)
Date: 01/21/05

  • Next message: Bauer, Henry: "Re: Dhcp security"
    To: Paul Aviles <paviles@adjoined.com>, focus-ms@securityfocus.com
    Date: Fri, 21 Jan 2005 08:35:43 -0000
    
    

    Implement rigorous physical and perimeter security for your network and be
    vigilant in maintaining such security.
    Upgrade any lingering Windows NT domains so you can make use of the DHCP
    server authorization feature of Active Directory.
    Avoid using Windows 2000 or Windows Server 2003 domain controllers as DHCP
    servers.
    Use reservations for assigning addresses of critical servers on your
    network, or use static addresses for them instead.

    Rigorous physical security i.e. no unsecured wall jacks, locked doors, staff
    trained to recognize social engineering attempts, and so on.

    -----Original Message-----
    From: Paul Aviles [mailto:paviles@adjoined.com]
    Sent: 19 January 2005 22:30
    To: focus-ms@securityfocus.com
    Subject: [Maybe Spam] Dhcp security

    I have a weird question maybe. Is there a way to prevent our DHCP from
    giving leases to computers not in our domain? I don't want anyone that
    walks in to just connect and have the possibility of a network viruses
    getting loose. Is this possible?

    My setup is a typical AD 2K environment, simple domain no empty root.

    Thanks

    Paul

    ---------------------------------------------------------------------------
    ---------------------------------------------------------------------------

    ---------------------------------------------------------------------------
    ---------------------------------------------------------------------------


  • Next message: Bauer, Henry: "Re: Dhcp security"

    Relevant Pages

    • << SBS News of the week - Sept 26 >>
      ... And he points to the info you need to put the file on the server in the ... at the network perimeter. ... The Symantec Firewall/VPN and the Gateway Security ... by the firewall at risk. ...
      (microsoft.public.backoffice.smallbiz2000)
    • Re: << SBS News of the week - Sept 26 >>
      ... > And he points to the info you need to put the file on the server in the ... > at the network perimeter. ... The Symantec Firewall/VPN and the Gateway Security ... An attacker can exploit these flaws in tandem via specially ...
      (microsoft.public.backoffice.smallbiz2000)
    • << SBS News of the week - Sept 26 >>
      ... And he points to the info you need to put the file on the server in the ... at the network perimeter. ... The Symantec Firewall/VPN and the Gateway Security ... by the firewall at risk. ...
      (microsoft.public.windows.server.sbs)
    • Re: << SBS News of the week - Sept 26 >>
      ... > And he points to the info you need to put the file on the server in the ... > at the network perimeter. ... The Symantec Firewall/VPN and the Gateway Security ... An attacker can exploit these flaws in tandem via specially ...
      (microsoft.public.windows.server.sbs)
    • << SBS News of the week - Sept 26 >>
      ... And he points to the info you need to put the file on the server in the ... at the network perimeter. ... The Symantec Firewall/VPN and the Gateway Security ... by the firewall at risk. ...
      (microsoft.public.backoffice.smallbiz)