Re: Windows 2003 server Network Security



Larry Bird wrote:
> I want to lock down my network from PCs for Laptops outside the company.
> Basically I do not want anyone to be able to plug in his or her laptop
> computer via an RJ45 connection and have any access to resources without
> signing in with a valid userid and password. I don't want them to have a
> DHCP IP address to surf the Internet unless authorized via their userid
> and
> password.
>
> Where do I start to implement these restrictions?

Your DHCP server should be configured to give out IPs based off something
you control - or you should not give out DHCP addresses.. One or the other
would be the quickest.

You could look into 802.1x authentication in your AD environment - that is
an option as well - since you mentioned you wanted them to have some sort of
authentication first.

The most effective - by far - however, would be the limiting by MAC
addresses.. A little more management-centric - in that you have to know
every MAC address of every machine that should be able to get an IP from
your DHCP server. Not in that list - then they (for the most part - unless
they are hackers with a purpose) have to come to you to get that MAC address
added to allow them to get a DHCP IP address.

--
Shenan Stanley
MS-MVP
--
How To Ask Questions The Smart Way
http://www.catb.org/~esr/faqs/smart-questions.html


.



Relevant Pages

  • Re: New motherboard installed, new startup coundown?
    ... | One of our laptops had a bad motherboard, and I sent it out to be ... and then the acro DHCP and then a DOS ... The exact words of the dos text are "Client MAC Address", ...
    (microsoft.public.windowsxp.perform_maintain)
  • Re: Preventing DHCP from allocating IPs
    ... Each segment is physically separate with a Linux ... unknown MAC addresses firstly don't get a DHCP ... >> wants access to your network, they will have to come to you to obtain ...
    (Security-Basics)
  • Re: Secure your DHCP
    ... I can only think of allocating via dhcp reservation using network card ... Create an exclusion of your whole DHCP scope (So no IP's are free to be ... assign each mac address an Ip address from what was in your pool. ...
    (microsoft.public.windows.server.sbs)
  • Re: Macintosh and audio live performance
    ... I am running win2k for 15 months on a 2.4 GHz celeron without any ... problem.IMHO the difference between a mac and a pc is that the mac comes ... tend to use macintosh laptops to produce music. ...
    (comp.os.linux.misc)
  • Re: saw the new Apple razor thin notebook
    ... Even though I use my laptops a lot when out and about, ... decide what to do on my Mac vs. PC laptops. ... Journals can automatically collect entries from other journals that ... Apple has the one on one training for $99 / year, ...
    (alt.sys.pc-clone.dell)