Networking Forums

Networking Forums > Computer Networking > Windows Networking > DHCP Authorization

Reply
Thread Tools Display Modes

DHCP Authorization

 
 
=?Utf-8?B?TWFyaw==?=
Guest
Posts: n/a

 
      02-10-2005, 06:17 PM
Why do you need to authorize a DHCP server when the server is a member of a
Domain? Where does it store the authorized server information and what does
it do special with the information? Is there a way around this with a
machine in the domain? What type of overhead is genterated by this?

Thanks

Mark
 
Reply With Quote
 
 
 
 
Miha Pihler [MVP]
Guest
Posts: n/a

 
      02-10-2005, 06:33 PM
Hi Mark,

An unauthorized DHCP server on a network can cause a variety of problems,
such as the leasing of incorrect IP addresses and options. To protect
against this type of problem, when a Windows 2000 or Windows Server 2003
domain member DHCP server attempts to start on the network, it first queries
Active Directory. The DHCP server compares its IP address and server name to
the list of authorized DHCP servers. If either the server name or IP address
is found on the list of authorized DHCP servers, the server is authorized as
a DHCP server. If no match is found, the server is not authorized in Active
Directory and does not respond to DHCP traffic. The process of authorizing
DHCP servers is useful for only Windows 2000-based or Windows Server
2003-based DHCP servers. This process cannot be used for DHCP servers
running Windows NT Server, or servers running non-Windows-based DHCP
services. Only a member of the Enterprise Admins group can authorize or
unauthorize a DHCP server in Active Directory.

Authorizing DHCP Servers in Active Directory
http://www.microsoft.com/resources/d...c_dhc_srnz.asp

I hope this helps.

--
Mike
Microsoft MVP - Windows Security

"Mark" <(E-Mail Removed)> wrote in message
news:A2557CF8-DC57-42A8-8AE4-(E-Mail Removed)...
> Why do you need to authorize a DHCP server when the server is a member of
> a
> Domain? Where does it store the authorized server information and what
> does
> it do special with the information? Is there a way around this with a
> machine in the domain? What type of overhead is genterated by this?
>
> Thanks
>
> Mark



 
Reply With Quote
 
=?Utf-8?B?TWFyaw==?=
Guest
Posts: n/a

 
      02-10-2005, 07:03 PM
Miha,

I have seen this article and yes it helps thanks but I am really interested
in what the process is. Is this basically just a list stored in LDAP that is
checked every so often by a DHCP server to see if it is authorized? what
overhead does this generated?

Thanks

Mark

"Miha Pihler [MVP]" wrote:

> Hi Mark,
>
> An unauthorized DHCP server on a network can cause a variety of problems,
> such as the leasing of incorrect IP addresses and options. To protect
> against this type of problem, when a Windows 2000 or Windows Server 2003
> domain member DHCP server attempts to start on the network, it first queries
> Active Directory. The DHCP server compares its IP address and server name to
> the list of authorized DHCP servers. If either the server name or IP address
> is found on the list of authorized DHCP servers, the server is authorized as
> a DHCP server. If no match is found, the server is not authorized in Active
> Directory and does not respond to DHCP traffic. The process of authorizing
> DHCP servers is useful for only Windows 2000-based or Windows Server
> 2003-based DHCP servers. This process cannot be used for DHCP servers
> running Windows NT Server, or servers running non-Windows-based DHCP
> services. Only a member of the Enterprise Admins group can authorize or
> unauthorize a DHCP server in Active Directory.
>
> Authorizing DHCP Servers in Active Directory
> http://www.microsoft.com/resources/d...c_dhc_srnz.asp
>
> I hope this helps.
>
> --
> Mike
> Microsoft MVP - Windows Security
>
> "Mark" <(E-Mail Removed)> wrote in message
> news:A2557CF8-DC57-42A8-8AE4-(E-Mail Removed)...
> > Why do you need to authorize a DHCP server when the server is a member of
> > a
> > Domain? Where does it store the authorized server information and what
> > does
> > it do special with the information? Is there a way around this with a
> > machine in the domain? What type of overhead is genterated by this?
> >
> > Thanks
> >
> > Mark

>
>
>

 
Reply With Quote
 
Miha Pihler [MVP]
Guest
Posts: n/a

 
      02-10-2005, 07:17 PM
AD is checked every time DHCP service starts. I am not sure about the
overhead. Can you be more specific what are your concerned about? Network
overhead? I believe this check would cause less traffic then client looking
for DHCP...

--
Mike
Microsoft MVP - Windows Security

"Mark" <(E-Mail Removed)> wrote in message
news:92D72F72-1006-450F-8AC0-(E-Mail Removed)...
> Miha,
>
> I have seen this article and yes it helps thanks but I am really
> interested
> in what the process is. Is this basically just a list stored in LDAP that
> is
> checked every so often by a DHCP server to see if it is authorized? what
> overhead does this generated?
>
> Thanks
>
> Mark
>
> "Miha Pihler [MVP]" wrote:
>
>> Hi Mark,
>>
>> An unauthorized DHCP server on a network can cause a variety of problems,
>> such as the leasing of incorrect IP addresses and options. To protect
>> against this type of problem, when a Windows 2000 or Windows Server 2003
>> domain member DHCP server attempts to start on the network, it first
>> queries
>> Active Directory. The DHCP server compares its IP address and server name
>> to
>> the list of authorized DHCP servers. If either the server name or IP
>> address
>> is found on the list of authorized DHCP servers, the server is authorized
>> as
>> a DHCP server. If no match is found, the server is not authorized in
>> Active
>> Directory and does not respond to DHCP traffic. The process of
>> authorizing
>> DHCP servers is useful for only Windows 2000-based or Windows Server
>> 2003-based DHCP servers. This process cannot be used for DHCP servers
>> running Windows NT Server, or servers running non-Windows-based DHCP
>> services. Only a member of the Enterprise Admins group can authorize or
>> unauthorize a DHCP server in Active Directory.
>>
>> Authorizing DHCP Servers in Active Directory
>> http://www.microsoft.com/resources/d...c_dhc_srnz.asp
>>
>> I hope this helps.
>>
>> --
>> Mike
>> Microsoft MVP - Windows Security
>>
>> "Mark" <(E-Mail Removed)> wrote in message
>> news:A2557CF8-DC57-42A8-8AE4-(E-Mail Removed)...
>> > Why do you need to authorize a DHCP server when the server is a member
>> > of
>> > a
>> > Domain? Where does it store the authorized server information and what
>> > does
>> > it do special with the information? Is there a way around this with a
>> > machine in the domain? What type of overhead is genterated by this?
>> >
>> > Thanks
>> >
>> > Mark

>>
>>
>>



 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
encoding after authorization 802.1x ted Wireless Internet 0 08-21-2008 10:33 AM
DHCP Authorization and Scope Activation Bob Simon Windows Networking 1 03-26-2007 11:10 PM
DHCP Child Domain Never finishes its authorization blueboy1894 Windows Networking 1 06-21-2006 11:20 AM
Remove DHCP authorization list Jenglot Windows Networking 1 09-18-2004 12:00 PM
Delegate DHCP server Authorization kuljits Windows Networking 0 02-25-2004 03:00 PM



1 2 3 4 5 6 7 8 9 10 11