Re: DHCP Question

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance



In article <eWtSfj4QKHA.4568@xxxxxxxxxxxxxxxxxxxx>, townsend@xxxxxxxx
says...

We frequently have outside companies come into our office and they need
Internet connectivity. While we always have a Comcast line availalbe, many
times these external users use our LAN line and get an IP from our DHCP
server, so they have access to our network. Is there someway we can
configure DHCP to only hand out addresses to those computers on our domain
(possibly using our FQDN with a wildcard as the client name --
*.mydomain.com) and prevent outside users from accessing our network?


Guests should be on a different Wireless access device, so they are not
on your network at all. Either put them in a DMZ area, since some
firewalls have more than one DMZ (and I'm not talking about the FAKE DMZ
you find in linksys/home NAT routers), setup rules for HTTP/HTTPS and
DNS, possibly SMTP and FTP and RD, and only give them the key to your
GUEST wireless network.

Never allow an unmanaged decice on your LOCAL network.

--
You can't trust your best friends, your five senses, only the little
voice inside you that most civilians don't even hear -- Listen to that.
Trust yourself.
spam999free@xxxxxxxxxx (remove 999 for proper email address)
.



Relevant Pages

  • RE: Active Directory and IIS on production servers, and clustering
    ... > the Microsoft-supported position (DB in the secured network ... DMZ, it makes sense to have a DMZ domain just in order to be able to easily ... cases, unless there is some pressing business need to make a trust, I would ... WRT putting IIS and a DC together, back in IIS 5.0 days, yes, that was a ...
    (Focus-Microsoft)
  • Re: [fw-wiz] Rationale of the great DMZ
    ... >DMZ and its implied security has changed. ... Network activity wouldn't ... >necessarily begin from the DMZ and be tunneled in to the internal network. ... >Commonly SSL accelerators terminate the SSL end point prior to the ...
    (Firewall-Wizards)
  • Re: Firewall and DMZ topology
    ... attacker cannot spread his influence across the network. ... If the DMZ resides between the public Internet and the ... Should the DMZ be behind the LAN and not split off at the firewall, ... > The Gartner Group just put Neoteris in the top of its Magic Quadrant, ...
    (Security-Basics)
  • RE: SUS server
    ... Where in my network should I place the SUS server? ... Everything inside my network can talk to the DMZ, ... SurfControl E-mail Filter for SMTP & Exchange leverages multiple layers of ...
    (Focus-Microsoft)
  • RE: 504 Proxy timeout only with SSL traffic
    ... the DMZ network is considered External to the ... this may have an effect when you access the DMZ. ... And can access all other HTTPS sites on the internet? ... that there may be something wrong with the proxy engine on the ISA, ...
    (microsoft.public.isa)