Re: Users connect unauthorize laptops to my network.

From: Steven L Umbach (sumbach_at_N0spam.ameritech.net)
Date: 04/22/04


Date: Thu, 22 Apr 2004 10:16:24 -0500

You can view dhcp leases to see who has a computer lease but I don't know of
a way to generate an event in the security log and that would give a false
sense of security as it will not prevent unathorized users from connecting
to the network with a properly configured static IP. In a smaller network
you could also use a scope that had nothing but reservations mapping mac
addresses to IP addresses.

Better solutions depending on network configuration and budget would be to
possibly use ipsec to protect data on sensitive computers or use switches
that can filter based on mac addresses or use 802.1X authentication
switches, requiring certificate machine authentication. --- Steve

http://www.dlink.com/products/?pid=87 -- an affordable swtich with mac
filtering and 802.1X port based authentication
http://www.nwfusion.com/research/2002/0506whatisit.html -- description of
802.1X

"Amil Fortuna" <Amil@NotRealEmail.edu> wrote in message
news:O2DpjzGKEHA.1892@TK2MSFTNGP09.phx.gbl...
> How can I find out when this event happen?
> Is DHCP able to genrate an event sink?
> Can DCHP create a log entry? when an IP address is assigned to a computer.
>
> Environment: w2k domain.
> Fully patched
> 2 DC's, 2 DHCP's 2 WINS
> Thanks
>
>



Relevant Pages

  • Re: WAKE ON LAN tool
    ... network you still have to go in an dmanually type MACs for each and every ... associated IP and MAC addresses. ... Do you know of a tool that will do Wake on Lan based on the DHCP leases? ... Do you know of any WOL tool that integrates/queries the DHCP leases ...
    (microsoft.public.windows.server.sbs)
  • RE: WEP alternative
    ... Try limiting the dhcp leases to known mac addresses only. ... I've set up a netgear wireless router in the office to allow greater ...
    (Security-Basics)
  • SMTP Unable to relay after rem SAV 9.0 from exchange 2003 server
    ... I checked the security log but did not see any authentication failures when ... If I allow relay from anonymousthe email can be sent. ... I turn on authentication the end user is prompted for a userid and password ...
    (microsoft.public.exchange.admin)
  • Re: MAC to IP resolution
    ... you are using dhcp check your dhcp leases for "unique ID". ... --- Steve ... > My error logs list a MAC address, ... > resolve the MAC to an IP, so I can resolve the IP to a ...
    (microsoft.public.win2000.networking)