Re: DHCP security



"danielv" <dvhirt@xxxxxxxxx> said:
I currently admin a small network of about 12 clients, all with fixed
ip schemas. Since this network is only growing to include more and more
clients I was thinking of using a DHCP server to handle ip
configuration on new clients. Ive already got that working. But my main
concern is how do you stop a rogue DHCP server from getting on the
network and giving fake information to some clients? And how about
unauthorized clients?

As "Old guy" wrote, you could monitor your network for DHCP responses
originated by other than your official server(s).

As for unauthorized clients, using DHCP doesn't actually change the
situation; there are a few things you could do (depending on your
hardware):
- keep switch ports disabled by default
- when opening switch ports, lock them to a single MAC address

.... but especially the latter of the two tends to be more nuisance than
help. However, a written, approved, and legally binding policy would
be one of the first things to have - just to make everyone in the
company aware that there are rules, and bending/breaking the rules will
not be tolerated. Of course, policy alone isn't enough - but without
a policy any technical obstacle is just an invitation to circumvent it.
--
Wolf a.k.a. Juha Laiho Espoo, Finland
(GC 3.0) GIT d- s+: a C++ ULSH++++$ P++@ L+++ E- W+$@ N++ !K w !O !M V
PS(+) PE Y+ PGP(+) t- 5 !X R !tv b+ !DI D G e+ h---- r+++ y++++
"...cancel my subscription to the resurrection!" (Jim Morrison)
.



Relevant Pages

  • RE: Migrating 2000 workstations to 2003 domain
    ... Your understanding is correct that static IP address and DNS suffix will be ... we don't use static IP address in a network with more ... address after you migrate those 1000 clients from NT to win2k3 domain. ... I suggest you add a DHCP server in the ...
    (microsoft.public.windows.server.migration)
  • Re: [SLE] is a dhcpserver related to 1 network card?
    ... Does anything prevent you from ditching the present dhcp server? ... I think having more than one dhcp-server in a network is asking for trouble. ... set up *one* dhcp server to serve all clients in both networks via two ... set up one dhcp server to serve all client ...
    (SuSE)
  • Re: FC6: kickstart, static ip
    ... I do kickstart installations and try to assign a static ip ... After a successful installation process the clients come up and try to ... reach a dhcp server (see dhcp discovers in a network trace). ...
    (Fedora)
  • Re: DDNS Issues
    ... not so much the DHCP server itself. ... the clients themselves can register directly with DNS instead of the DHCP ...
    (microsoft.public.windows.server.dns)
  • Re: Two DHCP Servers on Newtork?
    ... The clients, once assigned an IP, tend to keep it, so not a lot of pressure ... if you put SBS on this network its DHCP server will shut down in ... A friend of mine runs a small business and has a domain server running ... On the same network is a ADSL modem/router (Connected to the same ...
    (microsoft.public.windows.server.sbs)