Re: DHCP server authorization - how does it work?

From: Herb Martin (news_at_LearnQuick.com)
Date: 01/22/05


Date: Sat, 22 Jan 2005 00:00:51 -0600


"David" <David@discussions.microsoft.com> wrote in message
news:8E2EB475-42C9-4028-892A-AEF4AC92CB7E@microsoft.com...
> In an AD environment, a DHCP server must be authorized before giving out
> leases. But *how* is it enforced? I suspect there is some interaction
between
> the network stack and domain controllers, but I am not sure. Any
information
> is appreciated.

Two ways: One member servers check for the list at
the DC, and those (DHCP servers) who recognize that
authorization is invoked (by the domain having the list)
send out DHCP_INFORM message which non-Domain
Win2000+ DHCP servers will respect IF they receive
them (which usually means if they are on the same subnet
since it is a broadcast.)

[I had previously thought it might be a multicast.]

Google: [ dhcp authorization domain site:microsoft.com ]
<
http://www.microsoft.com/resources/documentation/WindowsServ/2003/standard/proddocs/en-us/Default.asp?url=/resources/documentation/WindowsServ/2003/standard/proddocs/en-us/sag_dhcp_imp_authorizingservers.asp >

-- 
Herb Martin


Relevant Pages

  • RE: Unauthorize DHCP Server Problem
    ... of authorized DHCP servers maintained in the directory service database. ... information about the root domain. ... Authorization does not apply if DHCP servers are ...
    (microsoft.public.windows.server.active_directory)
  • Re: Standalone Win2K Server
    ... The DCs is what sends out the broadcast to ... > shutdown any unauthorized DHCP servers. ... I also said these authorized DHCP servers broadcast the ... >> authorization is required, they operate normally. ...
    (microsoft.public.win2000.networking)
  • Re: Standalone Win2K Server
    ... Then authorization is irrelevant as there is "No domain" ... A better question (naive not ignorant) would be: ... the authorized DHCP servers broadcast ...
    (microsoft.public.win2000.networking)
  • Re: Is total domain Isolation possible?
    ... domain controllers have to be exempt from your IPsec policies. ... I still dream of the total isolation of the domain scenario. ... and DHCP servers, they will be pretty secure by default, but they ...
    (microsoft.public.windows.server.security)
  • DHCP Server Delegation
    ... I have several DHCP servers running on domain controllers, ... would like to allow the remote site administrators to manage the DHCP server ...
    (microsoft.public.win2000.active_directory)