RE: Dhcp security

From: Shawn Wall (sjwall_at_shaw.ca)
Date: 01/21/05

  • Next message: Nelson Brandon: "AW: IIS6 on W2k3 DCs"
    Date: Fri, 21 Jan 2005 07:33:18 -0700
    To: 'Paul Aviles' <paviles@adjoined.com>, focus-ms@securityfocus.com
    
    

    You could reserve every IP address on you DHCP server with MAC addresses
    from you known user base. A pain in the hump for sure. If you have network
    switches capable of L2 security you could lock down the ports to prevent
    unauthorized MAC addresses from connecting to the network to begin with.

    HTH

    -----Original Message-----
    From: Paul Aviles [mailto:paviles@adjoined.com]
    Sent: Wednesday, January 19, 2005 3:30 PM
    To: focus-ms@securityfocus.com
    Subject: Dhcp security

    I have a weird question maybe. Is there a way to prevent our DHCP from
    giving leases to computers not in our domain? I don't want anyone that walks
    in to just connect and have the possibility of a network viruses getting
    loose. Is this possible?

    My setup is a typical AD 2K environment, simple domain no empty root.

    Thanks

    Paul

    ---------------------------------------------------------------------------
    ---------------------------------------------------------------------------

    ---------------------------------------------------------------------------
    ---------------------------------------------------------------------------


  • Next message: Nelson Brandon: "AW: IIS6 on W2k3 DCs"

    Relevant Pages

    • RE: DHCP
      ... Asunto: Re: DHCP ... I am looking for a way to block any PC that plugs into my network ... Windows Server 2008 can do this, but I'm not sure about 2003. ... MAC, this server will send IP address and parameters for configure the ...
      (Security-Basics)
    • Re: dial-up to ethernet
      ... >255.255.255.0 (Mac agrees), network is ... >Especially about DHCP? ... then restart networking ("/etc/init.d/networking restart", ...
      (Debian-User)
    • RE: Blocked IP address - What is MAC 24:5e:0d:1c:06:b7 ?
      ... Can you elaborate some more about the DHCP question? ... Not sure why your get a different Mac address but on the terminal server you ... Also depends how your DHCP is setup, do you have DHCP on your network? ...
      (microsoft.public.windows.terminal_services)
    • Re: Preventing DHCP from allocating IPs
      ... Each segment is physically separate with a Linux ... unknown MAC addresses firstly don't get a DHCP ... >> wants access to your network, they will have to come to you to obtain ...
      (Security-Basics)
    • Re: Secure your DHCP
      ... I can only think of allocating via dhcp reservation using network card ... Create an exclusion of your whole DHCP scope (So no IP's are free to be ... assign each mac address an Ip address from what was in your pool. ...
      (microsoft.public.windows.server.sbs)