Re: DHCP ENCRYPTED TO DOMAIN MEMBERS

From: Roger Abell (mvpNOSpam_at_asu.edu)
Date: 10/28/04


Date: Thu, 28 Oct 2004 08:07:32 -0700

Well, you cannot use IPsec directly as the machines do
not yet have a configured IP stack.
You may want to look into a quarantine style use of an
initial vlan handed out to any machine by dhcp, followed
by configuration with an IP validly routable on the corp
network after checks.
Alternatively, and painfully, you could control this by
having all IPs in the DHCP scopes reserved by MAC
(Note: this one is fallible/spoofable).

-- 
Roger Abell
"Oseas Millan" <OseasMillan@discussions.microsoft.com> wrote in message
news:12D16F10-554D-47E6-AAE4-D841BB7C0AC6@microsoft.com...
> Good Day.
>
> We Have a big Client, and we need to implement DHCP security, the security
> consist is the only the domain members can have an IP via DHCP, the
visitors
> computers cannot obtain an IP via DHCP. I donīt know how implement this
> solution, I Was try whit IPSec without results.
>
> Thanks for  Help me.
>
>


Relevant Pages

  • Re: WiFi, WPA and DHCP
    ... laptop, configured for DHCP - and picking up DNS server details via DHCP, works everywhere else that I need to use it. ... So if it can only work at home with this manual configuration, I would have to select a special network configuration for home than for anywhere else, which would be a drag. ... Instead of automatic private addressing you can put all the static details in which will be used when no DHCP server is available. ... Other machines at home are allocated memorable private IP addresses - this helps when testing whether machines are on and using VNC to control the mac mini and change the music or programme the pc to record some TV while I am finishing off some work and can't be bothered to climb the stairs. ...
    (uk.telecom.broadband)
  • DHCP question
    ... I am looking at setting up a DHCP server for a large number of machines ... and am wondering something about the configuration if you could answer ... dynamically while the daemon is running and without causing a problem ...
    (Fedora)
  • Re: DHCP ENCRYPTED TO DOMAIN MEMBERS
    ... Can I Encrypt the acknowledge ip message by IPSec? ... > by configuration with an IP validly routable on the corp ... > having all IPs in the DHCP scopes reserved by MAC ... >> We Have a big Client, and we need to implement DHCP security, the security ...
    (microsoft.public.win2000.security)
  • Re: A little FYI
    ... > fix for a different problem or end up making the same configuration ... Maybe faulty network equipment, ... > to look at what might interfere with DHCP. ... you were not here as I was trying to get the card to stay ...
    (comp.security.firewalls)
  • Re: Moved DHCP server to DC, now only works for domain users
    ... Machines get an IP Config before the user can even login in the first ... If a machine got a Config from the Linksys box then it will keep ... "alive" it will try the Linksys box even of the Linksys DHCP Service ...
    (microsoft.public.windows.server.networking)