Re: DHCP security



On Tue, 2007-10-09 at 20:15 +0000, Mike C wrote:
Ashley M. Kirchner <ashley <at> pcraft.com> writes:
So the question now
is, is there some way to restrict traffic to only those assigned IPs
(through DHCP) and block anything else that happens to show up on the
network? Maybe through iptables somehow?

You can usually arrange to restrict machine that connect to only those with
specified MAC address on the connecting interface - whilst this can be worked
around by someone clever they would need to spoof the known MAC address of one
of the machine in your list - but it is safer than not having a restriction to
only known MAC addresses
HTH




You can use NetReg (http://netreg.sourceforge.net/) to strengthen your
dhcp access. On the other hand you can user arpwatch to see if a system
changes it's hw address. And last, but not least you can use an
authenticated firewall (NuFW comes right now into my mind).


HTH



Calin

=================================================
Isn't it strange that the same people that laugh at gypsy fortune
tellers take economists seriously?

--
fedora-list mailing list
fedora-list@xxxxxxxxxx
To unsubscribe: https://www.redhat.com/mailman/listinfo/fedora-list



Relevant Pages

  • Re: MAC --> IP address?
    ... > said assign a static ip from dhcp, based on the MAC ... > your laptop has. ... So if you have just a single laptop just restrict the addresses DHCP ...
    (Fedora)
  • Re: DHCP security
    ... is there some way to restrict traffic to only those assigned IPs ... You can usually arrange to restrict machine that connect to only those with ... around by someone clever they would need to spoof the known MAC address of one ...
    (Fedora)
  • Re: Cant Access ANY url from python (errno 61)
    ... my mac's MAC address is different from the MAC address shown ... wireless router at his apartment. ... restrict -6 default kod nomodify notrap nopeer noquery ...
    (comp.lang.python)
  • Re: Cant Access ANY url from python (errno 61)
    ... my mac's MAC address is different from the MAC address shown ... wireless router at his apartment. ... restrict -6 default kod nomodify notrap nopeer noquery ...
    (comp.lang.python)
  • RE: Network "Change Management"
    ... You can restrict DHCP to an allowed list of MAC addresses, ... gateway or DNS just sniffing the network, ... Even if you restrict your DHCP to an allowed list of MACs you will need ...
    (Focus-Linux)