Re: Block Unauthorized Computer



As others have mentioned managed switches with mac filtering can certainly
help and such switches have learning modes for existing mac addresses on the
network so that you don't have to enter them all manually. DHCP scopes with
only reservations may stop the computer from getting a dynamic IP but not
from a computer with a static IP on your network. Ipsec policies may be
something to look at to use for traffic between domain computers [excluding
domain controllers] which can prevent non domain computers from accessing
any domain computer other than domain controllers which can not use ipsec
policies for traffic between them and other non domain controller domain
computers. The link below explains how to do this. Most likely someone put a
laptop from home on your network. If that is against policy you may want to
reiterate that to everyone.

Steve

http://www.microsoft.com/technet/security/guidance/architectureanddesign/ipsec/default.mspx
http://support.microsoft.com/kb/254949 --- must read before implementing
any ipsec policies

"Dave Mackler" <dmackler@xxxxxxxxxxxxx> wrote in message
news:OOEYQ%238GIHA.4584@xxxxxxxxxxxxxxxxxxxxxxx
My servers are Server 2003, SP2. I have DHCP running well. I noticed a
computer name in the Address list of the DHCP server that is not a
computer that belongs to our company. All I have is the computer name and
MAC address, which DHCP catches.

How can I block or prohibit this computer from getting an IP address or
from using our network for whatever purpose??

dave Admin




.



Relevant Pages

  • TidBITS#794/29-Aug-05
    ... This week's issue brings a potpourri of Mac news, ... Mark Anbinder looks briefly at Google Talk, ... Adding Tiger's AirPort Preferred Network List ...
    (comp.sys.mac.digest)
  • Apples new software may steal the show
    ... Steve Jobs, Apple Computer's co-founder and performer in chief, rarely shows any reluctance to sell -- or even over-sell -- his company's accomplishments. ... Jobs spent only about five minutes talking about what I see as the big news of the day: Apple's first software for using a home network through a television screen rather than a computer monitor. ... Apple's Mac OS X, the software running all its Macintosh computers, also has built-in features for easily connecting Macs in a network. ...
    (comp.sys.mac.advocacy)
  • Re: OK first real Mac Complaint - Network Trouble
    ... changing the channel on my router has cleared up wireless issues on my ... have to reset it when the connection dies. ... to suck up a large amount of network bandwidth to do unnecessary screen ... It should at least help to identify what the Mac ...
    (comp.sys.mac.misc)
  • Re: About War Driving ..
    ... However, MAC filtering does not qualify as defense in depth, ... because the attacker can spoof a valid IP address. ... broadcasting the SSID doesn't hide a network, but just makes it show up ... machines in your building that you can control and check the MAC ...
    (Security-Basics)
  • Re: Wired security improvements
    ... I have a lot of experience with 802.1x in a wireless environment and it ... option than MAC Authentication via RADIUS as far as security is concerned, ... it can only provide a weak form of network authentication. ...
    (Security-Basics)