Jump to content

Question about DHCP Security


bbbngowc

Recommended Posts


Unfortunately, I don't think you can. When logging into a pc, it MUST have a valid IP address to communicate with the server in order for the credentials to be verified in AD. Remember, DHCP allocates an IP as soon as windows starts up on the client pc. One way to do it is to make reservations in DHCP based on the MAC addresses of the pc's that connect to the server and set the pool size to the number of pc's that will be in use.

Link to comment
Share on other sites

If your biggest concern is actually the security of your servers, you can configure IPsec in group policy. But as far as actual DHCP security goes, nitroshift's suggestion is the best I would come up with as well. In fact I've done just that in very small environments. Everything gets a DHCP reservation and the reservations make up the entire pool. This way you can at least push down network config changes (DNS server assignments for example) if need be.

DHCP by nature uses broadcasts, so if you wanted to completely eliminate any communication with unauthorized hosts you would need to configure the DHCP server to only accept packets from a white list of MAC addresses. But that's starting to get into the realm of micromanaging.

Link to comment
Share on other sites

If your biggest concern is actually the security of your servers, you can configure IPsec in group policy. But as far as actual DHCP security goes, nitroshift's suggestion is the best I would come up with as well. In fact I've done just that in very small environments. Everything gets a DHCP reservation and the reservations make up the entire pool. This way you can at least push down network config changes (DNS server assignments for example) if need be.

DHCP by nature uses broadcasts, so if you wanted to completely eliminate any communication with unauthorized hosts you would need to configure the DHCP server to only accept packets from a white list of MAC addresses. But that's starting to get into the realm of micromanaging.

Thanks Rogue :thumbup

Edited by nitroshift
Link to comment
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...