Re: how to restrict dhcp to authenticate domain users ?

From: Roger Abell (mvpNOSpam_at_asu.edu)
Date: 12/10/04

  • Next message: Roger Abell: "Re: Microsoft Audit Collection Services"
    Date: Thu, 9 Dec 2004 17:41:35 -0700
    
    

    The real problem here is that you have a catch-22: before the
    machine has an IP you really cannot tell much about what it is
    or what account is in use on it.

    One solution that has not been mentioned is use of a quarantine
    vlan, to which the dhcp clients have initial access. If subsequent
    tests are passed, they are then allowed out, and one of these test
    would be that the machine is domain joined or also that machine
    local accounts are not available for local login, only domain accts.

    Now, if someone can walk into the building lobby and plug in,
    and the network is not switched, then the only controls in the
    network are MAC based, then they will walk around you sooner
    or later, given some time or determination. So, to make a solution
    really sound, you need something like 802.1x, and then gate access
    with the quarantine vlan.

    -- 
    Roger Abell
    Microsoft MVP (Windows  Security)
    MCSE (W2k3,W2k,Nt4)  MCDBA
    "lmpbas" <lmpbas@yahoo.com> wrote in message
    news:OBd3%23sg3EHA.3336@TK2MSFTNGP11.phx.gbl...
    > We are having problem with people bringing their Laptop into the LAN. They
    > are unable to access the resources but they are able to surf.
    > How to restrict dhcp to authenticate domain users ?
    > Any ideas ?
    >
    > Thanks
    > lm
    >
    >
    

  • Next message: Roger Abell: "Re: Microsoft Audit Collection Services"

    Relevant Pages

    • Re: Word 2K Voice Recognition
      ... I would surmise that our real problem would have ... to do with isolating that part of our network restricting access to some critical piece ... asked Network Administration abuot possible restrictions? ... This reply is posted in the Newsgroup; please post any follow question or reply in the ...
      (microsoft.public.word.docmanagement)
    • Re: Three handover to O2
      ... >Thinking of getting the Moto V3x. ... I think this would only be a real problem if you live or work in a poor 3 ... I have used Voda 3G and whilst it is true, the 3g/GSM handover is seamless, ... the Voda 3G network coverage is useless and getting video service was more ...
      (uk.telecom.mobile)
    • Viewing Files Across Network
      ... We have a real problem here at work. ... Since upgrading to SP2, we cannot view ... files across the network. ...
      (microsoft.public.windowsxp.general)