RE: Blocking Access to Non-domain computers

From: DeGennaro, Gregory (Gregory_DeGennaro_at_csaa.com)
Date: 08/25/04

  • Next message: Don Parker: "RE: User Activity Monitoring"
    Date: Wed, 25 Aug 2004 07:14:18 -0700
    To: "Andreas" <andreas@inferno.nadir.org>, <security-basics@securityfocus.com>
    
    

    You can use MAC filtering, however if you are really paranoid, you
    should use a CA server which can be extended to the network level using
    802.1x. If you are not using Active Directory, you may want to migrate
    to AD and if you are paranoid, upgrade to Windows 2003 server and XP
    professional and take advantage of Ipsec Policy.

    http://www.microsoft.com/resources/documentation/WindowsServ/2003/all/de
    ployguide/en-us/Default.asp?url=/resources/documentation/WindowsServ/200
    3/all/deployguide/en-us/dnsbj_ips_overview.asp

    It seems to work really nice and have heard many good things about ipsec
    policy. Of course, if you encrypt traffic and you use a NIDS, you will
    need to have man-in-middle devices to unencrypt and sniff the packets
    and re-encrypt or you will need a HIDS on all devices.

    Regards,
     
    Greg DeGennaro Jr., CISSP, CCNP
    Systems Engineer

    -----Original Message-----
    From: Andreas [mailto:andreas@inferno.nadir.org]
    Sent: Monday, August 23, 2004 12:16 PM
    To: security-basics@securityfocus.com
    Subject: Re: Blocking Access to Non-domain computers

    Hello,

    On Thursday 19 August 2004 16:58, Brian Gehrke wrote:
    > I am running a W2K domain, using DHCP. Is it possible to block
    > non-domain computers from getting an IP address from the DHCP server,
    > so they will not be able to access the Internet through the network.

    is dhcp by mac address (which of course can easily be spoofed)
    an option?

    regards,
    andreas

    ------------------------------------------------------------------------

    ---
    Computer Forensics Training at the InfoSec Institute. All of our class
    sizes are guaranteed to be 12 students or less to facilitate one-on-one
    interaction with one of our expert instructors. Gain the in-demand
    skills of a certified computer examiner, learn to recover trace data
    left behind by fraud, theft, and cybercrime perpetrators. Discover the
    source of computer crime and abuse so that it never happens again.
    http://www.infosecinstitute.com/courses/computer_forensics_training.html
    ------------------------------------------------------------------------
    ----
    ---------------------------------------------------------------------------
    Computer Forensics Training at the InfoSec Institute. All of our class sizes
    are guaranteed to be 12 students or less to facilitate one-on-one
    interaction with one of our expert instructors. Gain the in-demand skills of
    a certified computer examiner, learn to recover trace data left behind by
    fraud, theft, and cybercrime perpetrators. Discover the source of computer
    crime and abuse so that it never happens again.
    http://www.infosecinstitute.com/courses/computer_forensics_training.html
    ----------------------------------------------------------------------------
    

  • Next message: Don Parker: "RE: User Activity Monitoring"

    Relevant Pages

    • Re: My posts cannot get througt to scs!
      ... who will believe your paranoid bullshit! ... You are idiot to compare the population to the number of entries especially if ... Your ISP confirmed that their news server were violated a few times, ... If these are not the work of the Singapore pap government ...
      (soc.culture.singapore)
    • Re: Fadal 3016 with 32MP control questions........... 2nd try
      ... server, and two identical DVD's. ... I can make an instant image without touching the "master" ... How's that for paranoid redundancy;>) ????? ... because the tape drive was ...
      (alt.machines.cnc)
    • Re: Licensing on SBS.. that 75 limit
      ... Handled at the network level, ... It's not an instant process, you need to do some preparation (as you would have to for ANY major install/reconfiguration of your server!), but it definitely works. ... One solution that may be of interest is to look at moving to Essential Business Server. ... It's not shipping yet, but getting close, and will provide a smooth transition to an environment that is a natural extension of what's been done in SBS, while giving you the ability to grow your business up to the 250 user/device range. ...
      (microsoft.public.windows.server.sbs)
    • Re: DHCP restriction via MAC...
      ... I wouldnt use MAC filtering, ... IPSec, ... Its based on IP so server would expect the ... >> denial of service attack to legitimate computers if the DHCP scope is ...
      (microsoft.public.security)
    • Re: Help with Security Ideas on new install
      ... If they so paranoid then disconect the connection the server from the ... > design the most secure solution posible, including ISA server, FE-BE ... What type of network security is currently in place, firewalls, ...
      (microsoft.public.exchange.admin)