Re: Blocking Access to Non-domain computers

From: Oleksandr Darchuk (o.darchuk_at_wucb.lviv.net)
Date: 08/25/04

  • Next message: Sanjay Tomar: "RE: company password keeping"
    Date: Wed, 25 Aug 2004 09:04:36 +0300
    To: Brian Gehrke <bjgehrke@sbcglobal.net>
    
    

    Brian Gehrke wrote:
    > I am running a W2K domain, using DHCP. Is it possible to block
    > non-domain computers from getting an IP address from the DHCP server, so
    > they will not be able to access the Internet through the network.

    With Nortel BayStack switches you can try to set up EAPoL with Microsoft
    RADIUS server. As I know, Microsoft RADIUS works with domain users. But
    I don't know about other vendors switches.
    But IMHO if you just want to block access to internet, possible it's
    better to use Proxy with auth (e.g Squid can auth users from W2k domain)
    Possible it helps.
    Regards.

    ---------------------------------------------------------------------------
    Computer Forensics Training at the InfoSec Institute. All of our class sizes
    are guaranteed to be 12 students or less to facilitate one-on-one
    interaction with one of our expert instructors. Gain the in-demand skills of
    a certified computer examiner, learn to recover trace data left behind by
    fraud, theft, and cybercrime perpetrators. Discover the source of computer
    crime and abuse so that it never happens again.

    http://www.infosecinstitute.com/courses/computer_forensics_training.html
    ----------------------------------------------------------------------------


  • Next message: Sanjay Tomar: "RE: company password keeping"

    Relevant Pages

    • Re: disable internet access non-domain user
      ... even if u are using DHCP, ... "Phillip Windell" wrote: ... I want to disable internet access to non-domain COMPUTERS ... non domain users will not be able to surf the internet:)) ...
      (microsoft.public.isa.configuration)
    • Re: XPSP2 / IAS / 802.1x / EAPOL / EAP-TLS / Cannot get DHCP lease
      ... that could be the reason try and see if you can get a DHCP lease if you move ... >> Client won't request an IP address from the radius server as would be the>> case with PPP & RAS so this "IP" tab won't help. ... > Just a thought here - the switch I am using for EAP is connected upstream> to a switch that is not running a high enough version of firmware to be> able to handle EAP. ...
      (microsoft.public.internet.radius)
    • internal wireless router config best practices
      ... Interested in best practices when setting up a wireless router for internal ... domain users so that they can be served by SBS's dhcp & have access as if ...
      (microsoft.public.windows.server.sbs)
    • dhcp
      ... On a win2000 active directory server runnign dhcp... ...
      (microsoft.public.win2000.active_directory)