Re: DHCP lease to Domain members only



"Rich L" <RichL@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:059CE40A-F1D9-4E94-9E63-1BBEB9E2AA1A@xxxxxxxxxxxxxxxx
Is there a way - or group policy - or anything I can do to lock down the
DHCP
server so that it only gives IP's out to those computers whose computer
accounts are registered in the Active Direcory?

No, not practically, but there are other ways to accomplish
this is you are serious enough (time and effort).

DHCP is a promiscuous service that is neither specific to
domain, OS, version or anything else particularly.

1) First way to fake it: Give every station a Reservation so
that no one with an unidentified NIC (MAC address) can
get one -- it's not truly secure but will stop causal abuse.

2): Setup a "User ClassID" on your DHCP server
scopes and give it to your client machines with
"ipconfig /setclassid".

3) Then override the DEFAULT but TERRIBLE settings on
the DHCP scope options with "ClassID options." (DNS,
Default Router, etc.) It's not secure either but it might
discourage them.

4) Install truly secure hubs/switches which use something
like PEAP, Certificates etc. to authenticate clients before
allowing network access.

5) Best but obnoxious to setup for this: IPSec and only
grant access to your network for those who can authenticate
using either domain (computer) account or certificate. This
doesn't actual address the DHCP issue but it is the most
secure. Combine with one or two of the others to get the
full effects.


--
Herb Martin, MCSE, MVP
Accelerated MCSE
http://www.LearnQuick.Com
[phone number on web site]


.



Relevant Pages

  • Re: IIS and webserver question
    ... "How about a secure feild emmiter running on the W2303 Box array and let the ... ihabitants access the warp core with a SSH positron tunnel effect, ... > How about a Secure Shell server running on the W2003 server box and ... You could also create individual accounts if desired... ...
    (microsoft.public.windowsxp.network_web)
  • Re: DHCP and DNS dynamic registration
    ... I think I have set in the DNS server to take both secure and non secure. ... I guess in the other domain where DHCP is not authorized, ...
    (microsoft.public.windows.server.general)
  • Re: Nmap questions concering my router
    ... >> DHCP can be made more secure, with extra work on the server application ... >> addresses on each computer than to set up DHCP securely. ... A basic DHCP setup will not do to be secure against spoofing. ...
    (comp.security.firewalls)
  • Re: Overwrite existing secure dns update with third part DHCP servers, is it possible?
    ... When used, this allows DHCP to register the record, but also ... Microsoft MVP (Windows Server System: ... > We have configured the DNA server to allow non secure and secure updates. ...
    (microsoft.public.windows.server.dns)
  • Re: Exchange not receiving inboud emails
    ... the SBS DHCP exclusion range. ... configuration the balance of the server configuration is in. ... > accounts and have not been able to receive any emails to them. ...
    (microsoft.public.windows.server.sbs)