Re: Re: DHCP Authorization in active directory.

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance



Ryan,

You might also consider enabling 802.1x with EAP to authenticate the
computer account before an IP address is even assigned. This would require
computer certificates on all machines and a well planned PKI.

--
Ryan Hanisco
MCSE, MCDBA
FlagShip Integration Services
Chicago, IL

"Paul" <Paul@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:2CA49A1C-5D63-4301-83C0-EF3005E4AC21@xxxxxxxxxxxxxxxx
> Infrastructure products to assist:
>
> Cisco ACS
> Cisco WLSE (Wireless)
>
> ** A Cisco Agent hooks into AD, then, when a client asks for an IP address
> the Cisco device simply asks for the AD credentials. If they match they
> get
> an IP, if they don't, no access.
>
> VLANs are also a way of helping limit unauthorized users to a degree.
>
> "MoscowHippy" wrote:
>
>> "ping2" wrote:
>> > Hi Lara, thanks for the info. I had a feeling that your answer
>> > would be no.
>> >
>> > It would be real nice if dhcp did auth against AD this would
>> > put an
>> > end to free internet access to rouge laptops. As I see it then
>> > there
>> > is no point in authorizing dhcp in active directory. I think
>> > ms intent
>> > was to try stop rouge dhcp servers from assigning bad ip's
>> > with this
>> > method.
>> >
>> > The problem with dhcp is that whatever dhcp server responds to
>> > a
>> > clients request first normally assigns the ip to the client.
>> > If you
>> > really want to hose a internal network just hook up a lowcost
>> > netgear
>> > router and hand out dhcp assignments on your subnet,,,
>> >
>> > I got about 200 client pc's on the network. In the above test
>> > the
>> > netgear typically bet MS Dhcp server in assinging ip's to the
>> > client.
>> > Needless to say they were the wrong ips.
>> >
>> > Thanks for your insight.
>> >
>> > JJ
>> >
>> >
>> >
>> >
>> >
>> > On 10 Jan 2005 14:51:44 -0500, lforbes
>> > <UseLinkToEmail@xxxxxxxxxxxxxxxxx> wrote:
>> >
>> > >Hi,
>> > >
>> > > > Here is what I am trying to accomplish. Person hooks
>> > up their
>> > > > laptop to company network. Laptop broadcasts for a
>> > dhcp assignment
>> > > > dhcp server responds. Dhcp server checks active
>> > directory for a
>> > > > valid user... None exists. Dhcp declines assigning
>> > the ip.
>> > >
>> > >I also posed this question a month back and the answer is no.
>> > DHCP
>> > >doesn't authenticate to AD and therefore anyone with a laptop
>> > can get
>> > >an IP. DHCP is not domain specific.
>> > >
>> > >The only way I have got around this somewhat is to install an
>> > ISA
>> > >server. The only reason my users plug their laptops in is to
>> > get
>> > >internet service. The ISA requires AD authentication so
>> > therefore no
>> > >internet service.
>> > >
>> > >I also scan my DHCP on a daily basis. All my Network Names
>> > are easily
>> > >identified and start with the same letter R for Room # eg.
>> > R123-123
>> > >
>> > >If I see an unidentified machines, I get the mac address and
>> > then
>> > >assign an ip like 192.0.0.0 which isn't a correct IP.
>> > >
>> > >Cheers,
>> > >
>> > >Lara
>>
>> I have also been looking for this, or a similar capability. While I
>> think that polling the active directory is a good idea, we have quite
>> a few wireless pda's that are not in active directory nor should be.
>>
>> I would rather have / build a table of authorized MAC addresses that
>> all DHCP servers could verify against before handing out an IP
>> address.
>>
>> request for address
>> server receives
>> verify valid mac address
>> if in table - yes, otherwise 0.0.0.0 and flag an admin staffer
>>
>> Granted, a dhcp scope reservation is exactly the solution, it defeats
>> the purpose of dhcp with my mobile (l)users. I would rather have one
>> table that all my servers point to with all authorized mac's so I
>> don't have to worry about what site, what subnet, etc.
>>
>> No valid MAC, No valid IP address
>>
>> Or if a script that watched the various scopes watching for change,
>> verifying each new address against the above prebuild table and
>> revoking licenses as they come up.
>>
>> For what it's worth...
>>
>> --
>> Posted using the http://www.WindowsForumz.com/ interface, at author's
>> request
>> Articles individually checked for conformance to usenet standards
>> Topic URL:
>> http://www.WindowsForumz.com/Active-Directory-DHCP-Authorization-ftopict248227.html
>> Visit Topic URL to contact author (reg. req'd). Report abuse:
>> http://www.WindowsForumz.com/eform.php?p=762163
>>


.



Relevant Pages

  • Re: DHCP server assigning ip addresses, does it is pinging it before?
    ... a client computer that is configured as a DHCP client sends out a broadcast packet called DHCPDISCOVER. ... This Discover packet contains the client's computer name and Media Access Control address so the DHCP servers can respond to it. ... Basically, the Discover packet says, "I'm looking for a DHCP server who can lease an IP address." ...
    (microsoft.public.windows.server.networking)
  • Re: Re: DHCP Authorization in active directory.
    ... Cisco WLSE ... >> is no point in authorizing dhcp in active directory. ... >> clients request first normally assigns the ip to the client. ... > all DHCP servers could verify against before handing out an IP ...
    (microsoft.public.win2000.active_directory)
  • Re: Double DNS records
    ... a DHCP server will assign same IP address to the client when he ... It doesn't make sense to have two DHCP servers on a single subnet. ... > the DNS is installt on both DC's. ...
    (microsoft.public.windows.server.dns)
  • Re: XP Does Not Accept DHCP Leases from new VLANs
    ... populating the CIADDR/"DHCP Option Field DHCP: ... The DHCP servers respond with a DHCPOFFER whch the client ... Option Field DHCP: Requested Address" fields with the old ...
    (microsoft.public.windowsxp.setup_deployment)
  • Re: Fixed Lease DHCP Doesnt Work After Connecting Different Netwo
    ... Shouldn't be the one on the network you aren't connected to! ... then changing back to DHCP. ... One way around this would be to do an ipconfig /release *before* shutting ... Why is this happening and who can I fix it without assigning myself ...
    (microsoft.public.windowsxp.network_web)