Re: Restricting DHCP to specific users



Neil,
You can't do it directly in DHCP. Your options, in order:
1) Limit the number of IP addresses in the pool, and give them all a fixed
reservation for the machines you want to connect. Then anything else will
not get an address
2) Assign the ports on the switch to specified MACs. You can also create a
separate VLAN connected only to the internet, and connect other ports to
this one
3) Set up a wireless network with connection only to the internet. Assign
all ports on the switch to Allowed computers.
4) Cisco Network Admission Control, or similar
5) Windows Server 2008 Network Access Protection
Hope that helps,
Anthony, http://www.airdesk.com



"Neil" <bothranilesh@xxxxxxxxx> wrote in message
news:3bb44231-b032-4c1f-a441-b0a88ab61a2a@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
We often have users at branch offices bringing their laptops from
home. As always these systems pose a security risk.

How can I have my DHCP server NOT assign IP address to these untrusted
users.

OR

Is there a way so that these users get a diff IP address and I can
move them to a different vlan

Thank you for your help.


.



Relevant Pages

  • Re: assigning ip addresses on a secure way
    ... DHCP works off of broadcasts. ... has network access to a DHCP server can get an address as long as there are address ... allows you to filter mac addresses in a learn mode that can lock ports to the current ... Only W2K, XP Pro, and Windows 2003 are ipsec aware. ...
    (microsoft.public.security)
  • RE: Preventing DHCP from allocating IPs
    ... The ethernet ports in these areas will be ... These areas are ACL'ed off from our enterprise network. ... > Turn of DHCP!! ... Preventing DHCP from allocating IPs ...
    (Security-Basics)
  • Re: active directory with external router
    ... it is possible but it is better to use windows server as DHCP and DNS. ... How to Setup Windows, Network, Remote Access on http://www.HowToNetworking.com ...
    (microsoft.public.windows.server.networking)
  • RE: About War Driving ..
    ... The students with wireless laptops are the only computers with DHCP ... The ports are bound to an IP and if you don't have it right, ... Whatever size network. ... Detect Malicious Web Content and Exploits in Real-Time. ...
    (Security-Basics)
  • Re: DHCP - Check Pre-Reqs before giving address
    ... to the network, not DHCP leases. ... > No Windows Server 2003 does not do this with DHCP servers. ...
    (microsoft.public.security)

Loading