Networking Forums

Networking Forums > Computer Networking > Windows Networking > How do i prevent someone from accesing my LAN

Reply
Thread Tools Display Modes

How do i prevent someone from accesing my LAN

 
 
MSExchangeStudent
Guest
Posts: n/a

 
      08-13-2007, 09:11 AM
Hi all

I have a win 2003 Server SP2 which is my domain controller and DHCP on it.
From time to time someone plug in a laptop into a network point; get a IP;
and can then use the internet, etc. How do i prevent someone from just
plugging in the network cable and having access to my network. Except
obviously reserving a IP for all the MAC adresses on my network; which will
take me a year to do. Anthing i can block him from getting a IP from DHCP or
maybe let he get a message to contact the system administrator.... Hope this
is clear


 
Reply With Quote
 
 
 
 
Phillip Windell
Guest
Posts: n/a

 
      08-13-2007, 03:19 PM
"MSExchangeStudent" <(E-Mail Removed)> wrote in message
news:%(E-Mail Removed)...

> I have a win 2003 Server SP2 which is my domain controller and DHCP on it.
> From time to time someone plug in a laptop into a network point; get a IP;
> and can then use the internet, etc. How do i prevent someone from just
> plugging in the network cable and having access to my network. Except
> obviously reserving a IP for all the MAC adresses on my network; which
> will take me a year to do. Anthing i can block him from getting a IP from
> DHCP or maybe let he get a message to contact the system administrator....
> Hope this is clear


Options:

1. A big gaurd dog that doesn't like laptops

2. Don't use DHCP

3. Don't let your wall jacks be available to the public (secure your
physical building)

4. Don't leave your wall jacks "hot". Unplug the patch cable at the MDF of
IDF when there is not a legitament user using it.

5. Buy the capable equipment and research how to deploy the 802.1x standard
(assuming I got my 802 numbers correct). It is a type of pre-authentication
that requires a certain amount of authentication before the Client is
allowed to get a IP configuration for the LAN.

6. Disable/remove/disconnect the cabling and go with Wireless that is using
at least WPA encryption,...then no one can get on the LAN without the "key".
Have a separate WAP for Guests that is on its own subnet that you can leave
turned off until it is actually needed for someone,...that is obvioulsy the
same theory as leaving the wall jacks "dead" until needed on the wired
system. Since it would only be turned on "as needed" and would be on a
separate subnet you could possibly leave it unsecured.

--
Phillip Windell
www.wandtv.com

The views expressed, are my own and not those of my employer, or Microsoft,
or anyone else associated with me, including my cats.
-----------------------------------------------------


 
Reply With Quote
 
SeriousSam
Guest
Posts: n/a

 
      08-13-2007, 04:51 PM
I liked the Guard dog option best, Mr. Windell hahaha. That was fun.
Although I have never actually done it, I know it is also possible to use
Vendor Class iD to limit access to your DHCP scope. Here is a link that
discusses it. http://support.microsoft.com/kb/240247 . Hope that helps!


"MSExchangeStudent" <(E-Mail Removed)> wrote in message
news:%(E-Mail Removed)...
> Hi all
>
> I have a win 2003 Server SP2 which is my domain controller and DHCP on it.
> From time to time someone plug in a laptop into a network point; get a IP;
> and can then use the internet, etc. How do i prevent someone from just
> plugging in the network cable and having access to my network. Except
> obviously reserving a IP for all the MAC adresses on my network; which
> will take me a year to do. Anthing i can block him from getting a IP from
> DHCP or maybe let he get a message to contact the system administrator....
> Hope this is clear
>



 
Reply With Quote
 
Phillip Windell
Guest
Posts: n/a

 
      08-13-2007, 04:52 PM

"SeriousSam" <(E-Mail Removed)> wrote in message
news:(E-Mail Removed)...
>I liked the Guard dog option best, Mr. Windell hahaha. That was fun.


:-)

> Although I have never actually done it, I know it is also possible to use
> Vendor Class iD to limit access to your DHCP scope. Here is a link that
> discusses it. http://support.microsoft.com/kb/240247 . Hope that helps!


Ok.

--
Phillip Windell
www.wandtv.com

The views expressed, are my own and not those of my employer, or Microsoft,
or anyone else associated with me, including my cats.
-----------------------------------------------------


 
Reply With Quote
 
MSExchangeStudent
Guest
Posts: n/a

 
      08-14-2007, 07:47 AM
Thank you phillip and SeriousSam

"Phillip Windell" <(E-Mail Removed)> wrote in message
news:ug$(E-Mail Removed)...
>
> "SeriousSam" <(E-Mail Removed)> wrote in message
> news:(E-Mail Removed)...
>>I liked the Guard dog option best, Mr. Windell hahaha. That was fun.

>
> :-)
>
>> Although I have never actually done it, I know it is also possible to
>> use Vendor Class iD to limit access to your DHCP scope. Here is a link
>> that discusses it. http://support.microsoft.com/kb/240247 . Hope that
>> helps!

>
> Ok.
>
> --
> Phillip Windell
> www.wandtv.com
>
> The views expressed, are my own and not those of my employer, or
> Microsoft, or anyone else associated with me, including my cats.
> -----------------------------------------------------
>
>



 
Reply With Quote
 
Rayees
Guest
Posts: n/a

 
      08-16-2007, 05:58 AM
Hi

Based on the scenario described by your, I suggest you to use Network
admission control (NAC). Which will solve your problem.

Analyse the complete need, you must use DHCP Enforcer along with 802.1x
which can solve the purpose. At this moment microsoft don't have any out of
box solution and the NAC is going to be part of Windows server 2008.

If you can't wait till that time, you can use thirdparty product like CISCO
NAC or Symantec NAC.

Regards
Rayees


 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Accesing c drive Tom B Windows Networking 1 05-06-2006 11:53 PM
View users accesing shared folder? ___Newbie___ Windows Networking 0 12-06-2005 01:44 AM
accesing an exchange server throught DSL and router Raul Network Routers 1 01-11-2005 02:03 AM
Accesing resources from trusted domain =?Utf-8?B?Y29vbGhhbmRz?= Windows Networking 0 09-25-2004 04:39 PM
Server 2003 has slow performance accesing Files on W2k Shares PowerFET Windows Networking 1 08-26-2004 01:52 PM



1 2 3 4 5 6 7 8 9 10 11