Re: Dhcp security

From: Bauer, Henry (Henry.Bauer_at_lendingtree.com)
Date: 01/21/05

  • Next message: Laura A. Robinson: "RE: IIS6 on W2k3 DCs"
    To: Paul Aviles <paviles@adjoined.com>
    Date: Fri, 21 Jan 2005 10:43:59 -0500
    
    

    A more comprehensive way to accomplish the same thing is ethernet MAC
    locking your switch. Ciscos, at least, can be told to learn one MAC,
    then if anything else is plugged in, it disables the port. You don't
    have to configure each MAC. Manually disable any unused port.

    This method has the advantage of also guarding against the case of
    someone assigning themselves an IP without using DHCP (by just
    configuring an IP manually).

    The tradeoff is you need an admin to plug in any new equipment.

    On Wed, 2005-01-19 at 17:29 -0500, Paul Aviles wrote:
    > I have a weird question maybe. Is there a way to prevent our DHCP from
    > giving leases to computers not in our domain? I don't want anyone that
    > walks in to just connect and have the possibility of a network viruses
    > getting loose. Is this possible?
    >
    > My setup is a typical AD 2K environment, simple domain no empty root.
    >
    > Thanks
    >
    > Paul
    >
    > ---------------------------------------------------------------------------
    > ---------------------------------------------------------------------------

    ---------------------------------------------------------------------------
    ---------------------------------------------------------------------------


  • Next message: Laura A. Robinson: "RE: IIS6 on W2k3 DCs"

    Relevant Pages

    • Re: Preventing DHCP from allocating IPs
      ... Each segment is physically separate with a Linux ... unknown MAC addresses firstly don't get a DHCP ... >> wants access to your network, they will have to come to you to obtain ...
      (Security-Basics)
    • Re: Secure your DHCP
      ... I can only think of allocating via dhcp reservation using network card ... Create an exclusion of your whole DHCP scope (So no IP's are free to be ... assign each mac address an Ip address from what was in your pool. ...
      (microsoft.public.windows.server.sbs)
    • Re: static IP addresses on LAN
      ... One Mac is an intel iMac, ... it is connected to the network and internet... ... If I instead configure it to use DHCP, then it gets assigned the wrong IP ... The other possibility is that you have more than 1 router. ...
      (comp.sys.mac.system)
    • Re: works on desk computer but not on wireless laptop
      ... RARP server, the DHCP server, or manually? ... So I chose that and now it wants to know the DHCP Client ID. ... And a 12 character number like a Mac ID. ... The OEM computer MAC address is the same as the DHCP ...
      (alt.internet.wireless)
    • RE: How do you keep users from stealing other users ip??
      ... Could it be the lease ... dhcp leases (don't forget, in the typical dhcp-request conversation, the ... allow them to change their mac address. ... What you have to do is when a new person hooks into the network, ...
      (freebsd-questions)

  • Quantcast