Go Back   TechArena Community > Technical Support > Computer Help > Windows Server > Active Directory
Become a Member!
Forgot your username/password?
Register Tags Active Topics RSS Search Mark Forums Read SiteMap

Tags: ,

Sponsored Links



DHCP Restriction

Active Directory


Reply
 
Thread Tools Search this Thread
  #1  
Old 03-02-2010
Rajnish
 
Posts: n/a
DHCP Restriction

we run our network with DHCP, this means anyone can
connect a laptop to our system and get an IP and start surfing the
internet and connect any virus infected PC to our network. Can I restrict
DHCP to
only issue IP's to Domain member computers .Basically I want to stop any
one (visitor) from getting a net
connection. I have Win2k3 Enviroement which ahs Web/DB/Application Servers
printers etc etc. Can it be done. Any option thru doing it thru Group is
available?

Early reply from this forum is truly appreciated
Reply With Quote
  #2  
Old 04-02-2010
Jonathan de Boyne Pollard
 
Posts: n/a
Re: DHCP Restriction



Early reply from this forum is truly appreciated




Why not go and read what Mitch Tulloch has to say on this subject, instead?

Reply With Quote
  #3  
Old 04-02-2010
Paul Bergson [MVP-DS]
 
Posts: n/a
Re: DHCP Restriction

You should look at NAP. To truly get this to work correctly, you will want
to have control at the switch level, thereby only allowing connection of
predefined clients.

http://www.microsoft.com/latam/windo...rotection.mspx


--
Paul Bergson
MVP - Directory Services
MCTS, MCT, MCSE, MCSA, Security+, BS CSci
2008, 2003, 2000 (Early Achiever), NT4
Microsoft's Thrive IT Pro of the Month - June 2009

http://www.pbbergs.com

Please no e-mails, any questions should be posted in the NewsGroup This
posting is provided "AS IS" with no warranties, and confers no rights.

"Rajnish" <Rajnish@discussions.microsoft.com> wrote in message
news:A67C8D87-72E6-4036-9BF9-6038C6C009DD@microsoft.com...
> we run our network with DHCP, this means anyone can
> connect a laptop to our system and get an IP and start surfing the
> internet and connect any virus infected PC to our network. Can I restrict
> DHCP to
> only issue IP's to Domain member computers .Basically I want to stop any
> one (visitor) from getting a net
> connection. I have Win2k3 Enviroement which ahs Web/DB/Application Servers
> printers etc etc. Can it be done. Any option thru doing it thru Group is
> available?
>
> Early reply from this forum is truly appreciated



Reply With Quote
  #4  
Old 04-02-2010
Ace Fekay [MVP-DS, MCT]
 
Posts: n/a
Re: DHCP Restriction

"Rajnish" <Rajnish@discussions.microsoft.com> wrote in message
news:A67C8D87-72E6-4036-9BF9-6038C6C009DD@microsoft.com...
> we run our network with DHCP, this means anyone can
> connect a laptop to our system and get an IP and start surfing the
> internet and connect any virus infected PC to our network. Can I restrict
> DHCP to
> only issue IP's to Domain member computers .Basically I want to stop any
> one (visitor) from getting a net
> connection. I have Win2k3 Enviroement which ahs Web/DB/Application Servers
> printers etc etc. Can it be done. Any option thru doing it thru Group is
> available?
>
> Early reply from this forum is truly appreciated



Another option is to use QIP, a third party DHCP utility that does just
this.

Alcatel-Lucent VitalQIP™ DNS/DHCP IP Address Management
SoftwareAlcatel-Lucent VitalQIP DNS/DHCP IP Address Management Software is a
market leading solution for automating IP address management services across
networks.
http://enterprise.alcatel-lucent.com...&page=overview


--
Ace

This posting is provided "AS-IS" with no warranties or guarantees and
confers no rights.

Please reply back to the newsgroup or forum for collaboration benefit among
responding engineers, and to help others benefit from your resolution.

Ace Fekay, MVP, MCT, MCITP EA, MCTS Windows 2008 & Exchange 2007, MCSE &
MCSA 2003/2000, MCSA Messaging 2003
Microsoft Certified Trainer
Microsoft MVP - Directory Services

If you feel this is an urgent issue and require immediate assistance, please
contact Microsoft PSS directly. Please check http://support.microsoft.com
for regional support phone numbers.


Reply With Quote
  #5  
Old 06-02-2010
Andrei Ungureanu
 
Posts: n/a
Re: DHCP Restriction

NAP should be the right way to do this, but as he is running W2K3, probably
he'll need to look at an IPSEC domain isolation scenario (or something
derived from that).

Andrei
www.winadmins.net

"Paul Bergson [MVP-DS]" <pbbergs@no_spammsn.com> wrote in message
news:eY4QbzZpKHA.2076@TK2MSFTNGP05.phx.gbl...
> You should look at NAP. To truly get this to work correctly, you will
> want to have control at the switch level, thereby only allowing connection
> of predefined clients.
>
> http://www.microsoft.com/latam/windo...rotection.mspx
>
>
> --
> Paul Bergson
> MVP - Directory Services
> MCTS, MCT, MCSE, MCSA, Security+, BS CSci
> 2008, 2003, 2000 (Early Achiever), NT4
> Microsoft's Thrive IT Pro of the Month - June 2009
>
> http://www.pbbergs.com
>
> Please no e-mails, any questions should be posted in the NewsGroup This
> posting is provided "AS IS" with no warranties, and confers no rights.
>
> "Rajnish" <Rajnish@discussions.microsoft.com> wrote in message
> news:A67C8D87-72E6-4036-9BF9-6038C6C009DD@microsoft.com...
>> we run our network with DHCP, this means anyone can
>> connect a laptop to our system and get an IP and start surfing the
>> internet and connect any virus infected PC to our network. Can I restrict
>> DHCP to
>> only issue IP's to Domain member computers .Basically I want to stop any
>> one (visitor) from getting a net
>> connection. I have Win2k3 Enviroement which ahs Web/DB/Application
>> Servers
>> printers etc etc. Can it be done. Any option thru doing it thru Group is
>> available?
>>
>> Early reply from this forum is truly appreciated

>
>

Reply With Quote
  #6  
Old 08-02-2010
Paul Bergson [MVP-DS]
 
Posts: n/a
Re: DHCP Restriction

Ah yes, I didn't catch that and agree on your ipsec solution.

--
Paul Bergson
MVP - Directory Services
MCTS, MCT, MCSE, MCSA, Security+, BS CSci
2008, 2003, 2000 (Early Achiever), NT4
Microsoft's Thrive IT Pro of the Month - June 2009

http://www.pbbergs.com

Please no e-mails, any questions should be posted in the NewsGroup This
posting is provided "AS IS" with no warranties, and confers no rights.

"Andrei Ungureanu" <someone@mydomain.com> wrote in message
news:OW1TJYzpKHA.3792@TK2MSFTNGP06.phx.gbl...
> NAP should be the right way to do this, but as he is running W2K3,
> probably he'll need to look at an IPSEC domain isolation scenario (or
> something derived from that).
>
> Andrei
> www.winadmins.net
>
> "Paul Bergson [MVP-DS]" <pbbergs@no_spammsn.com> wrote in message
> news:eY4QbzZpKHA.2076@TK2MSFTNGP05.phx.gbl...
>> You should look at NAP. To truly get this to work correctly, you will
>> want to have control at the switch level, thereby only allowing
>> connection of predefined clients.
>>
>> http://www.microsoft.com/latam/windo...rotection.mspx
>>
>>
>> --
>> Paul Bergson
>> MVP - Directory Services
>> MCTS, MCT, MCSE, MCSA, Security+, BS CSci
>> 2008, 2003, 2000 (Early Achiever), NT4
>> Microsoft's Thrive IT Pro of the Month - June 2009
>>
>> http://www.pbbergs.com
>>
>> Please no e-mails, any questions should be posted in the NewsGroup This
>> posting is provided "AS IS" with no warranties, and confers no rights.
>>
>> "Rajnish" <Rajnish@discussions.microsoft.com> wrote in message
>> news:A67C8D87-72E6-4036-9BF9-6038C6C009DD@microsoft.com...
>>> we run our network with DHCP, this means anyone can
>>> connect a laptop to our system and get an IP and start surfing the
>>> internet and connect any virus infected PC to our network. Can I
>>> restrict
>>> DHCP to
>>> only issue IP's to Domain member computers .Basically I want to stop
>>> any
>>> one (visitor) from getting a net
>>> connection. I have Win2k3 Enviroement which ahs Web/DB/Application
>>> Servers
>>> printers etc etc. Can it be done. Any option thru doing it thru Group is
>>> available?
>>>
>>> Early reply from this forum is truly appreciated

>>
>>



Reply With Quote
Reply

  TechArena Community > Technical Support > Computer Help > Windows Server > Active Directory


Thread Tools Search this Thread
Search this Thread:

Advanced Search


Similar Threads for: "DHCP Restriction"
Thread Thread Starter Forum Replies Last Post
How to deal with Rogue DHCP or DHCP Spoofing? racer Guides & Tutorials 1 03-11-2011 04:12 PM
Migration of DHCP Scopes from 1 DHCP Server to another DHCP Server Tarun Sood Active Directory 4 14-07-2009 06:48 PM
Active Directory Integrated DNS-DHCP -> DHCP computers with Pen Ic Kashif Windows Server Help 1 14-04-2009 01:28 AM
WDS 2008, DHCP, multiple VLANs, DHCP Relays, help! :-) Brian Day Windows Server Help 3 08-06-2008 08:09 AM
DHCP on SBS 2003 - BAD_ADDRESS in DHCP lease list Rene Brehmer Small Business Server 3 27-02-2008 04:16 AM


All times are GMT +5.5. The time now is 09:52 PM.