Advertisement

05.06.2008 at 09:19PM PDT, ID: 23381625 | Points: 500
[x]
Attachment Details
group policy editor to disallow computers to join the domain or get network access
if dhcp wont work , what should I use instead to prevent unauthorized access to the network? Can I configure the group policy object editor to prevent computers from joining the domain or getting network access in a windows server 2003? What are steps to go about this?
Start your free trial to view this solution
Question Stats
Zone: Networking
Question Asked By: xtin
Question Asked On: 05.06.2008
Participating Experts: 4
Points: 500
Views: 0
Translate:
Loading Advertisement...
05.06.2008 at 10:07PM PDT, ID: 21513295

Rank: Genius

All comments and solutions are available to Premium Service Members only.

Start your 7 day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
05.06.2008 at 10:08PM PDT, ID: 21513298

All comments and solutions are available to Premium Service Members only.

Start your 7 day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
05.06.2008 at 10:11PM PDT, ID: 21513309

Rank: Genius

All comments and solutions are available to Premium Service Members only.

Start your 7 day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
05.06.2008 at 10:17PM PDT, ID: 21513325

All comments and solutions are available to Premium Service Members only.

Start your 7 day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
05.06.2008 at 10:25PM PDT, ID: 21513351

All comments and solutions are available to Premium Service Members only.

Start your 7 day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
05.06.2008 at 10:28PM PDT, ID: 21513358

Rank: Genius

All comments and solutions are available to Premium Service Members only.

Start your 7 day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
05.06.2008 at 10:48PM PDT, ID: 21513419

All comments and solutions are available to Premium Service Members only.

Start your 7 day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
05.07.2008 at 06:35AM PDT, ID: 21516210

All comments and solutions are available to Premium Service Members only.

Start your 7 day free trial and see for yourself why Experts Exchange is the easiest and most proven technology resource in the world. Get Started

Already a member? Login to view this solution.

 
 
Loading Advertisement...
Microsoft
  • Internet Protocols
  • Applications
  • Development
  • OS
  • Hardware
  • Windows Security
Apple
  • Operating Systems
  • Hardware
  • Programming
  • Networking
  • Software
Internet
  • Search Engines
  • File Sharing
  • WebTrends / Stats
  • Spy / Ad Blockers
  • Web Browsers
  • New Net Users
  • Web Development
  • Chat / IM
  • Anti Spam
  • Web Servers
  • Anti-Virus
  • Email Clients
Gamers
  • Tips
  • Online / MMORPG
  • Puzzle
  • Emulators
  • Action / Adventure
  • Role Playing
  • Consoles
  • Game Programming
  • Strategy
  • Sports
  • Misc
  • Computer Games
Digital Living
  • Hardware
  • New Net Users
  • New Users
  • Software
  • Digital Music
  • Gaming World
  • Home Security
  • Apple
  • Networking Hardware
Virus & Spyware
  • Vulnerabilities
  • IDS
  • Encryption
  • Anti-Virus
  • Operating Systems Security
  • Software Firewalls
  • WebApplications
  • Cell Phones
  • Operating Systems
  • Internet
  • Hardware Firewalls
Hardware
  • Handhelds / PDAs
  • Displays / Monitors
  • Components
  • Networking Hardware
  • Peripherals
  • Laptops/Notebooks
  • Storage
  • Servers
  • Desktops
  • New Users
  • Misc
  • Apple
Software
  • System Utilities
  • Industry Specific
  • Network Management
  • Photos / Graphics
  • Page Layout
  • VMWare
  • Misc
  • Web Development
  • OS
  • CYGWIN
  • Voice Recognition
  • Message Queue
  • Quality Assurance
  • Security
  • Firewalls
  • MultiMedia Applications
  • Development
  • Database
  • Office / Productivity
  • Business Management
  • OS/2 Apps
  • Server Software
  • Internet / Email
ITPro
  • OS
  • Storage
  • Encryption
  • Operating Systems Security
  • Apple Hardware
  • Laptops & Notebooks
  • Servers
  • Networking Hardware
  • Peripherals
  • Devices
  • Displays / Monitors
  • WebTrends / Stats
  • Search Engines
  • Firewalls
  • WebApplications
  • IDS
  • Vulnerabilities
  • Email Clients
  • File Sharing
  • Spy / Ad Blockers
  • Web Browsers
  • Web Servers
  • Networking
  • Anti-Virus
  • Chat / IM
  • Anti Spam
Developer
  • Web Servers
  • Web Browsers
  • Game Programming
  • Dev Tools
  • Industry Specific
  • Office / Productivity
  • Database
  • CYGWIN
  • Web Development
  • Search Engines
  • File Sharing
  • WebTrends / Stats
  • Programming
  • Content Management
  • Application Servers
  • Protocols
Storage
  • Removable Backup Media
  • Storage Technology
  • Servers
  • Grid
  • Remote Access
  • Backup / Restore
  • Misc
  • Hard Drives
OS
  • Miscellaneous
  • Security
  • Development
  • Linux
  • VMWare
  • MainFrame OS
  • Unix
  • Apple
  • OS / 2
  • AS / 400
  • BeOS
  • Microsoft
  • VMS / OpenVMS
Database
  • Oracle
  • Miscellaneous
  • MySQL
  • Software
  • Sybase
  • Contact Management
  • PostgreSQL
  • Data Manipulation
  • Clarion
  • InterSystems Cache
  • Siebel
  • MUMPS
  • OLAP
  • SQLBase
  • SAS
  • GIS & GPS
  • 4GL
  • Berkeley DB
  • DB2
  • Informix
  • Interbase / Firebird
  • FoxPro
  • Reporting
  • LDAP
  • Filemaker Pro
  • MS SQL Server
  • dBase
  • MS Access
Security
  • Misc
  • Web Browsers
  • Software Firewalls
  • Operating Systems Security
  • File Sharing
  • Spy / Ad Blockers
  • Vulnerabilities
  • WebApplications
  • IDS
  • Anti-Virus
  • Encryption
  • Anti Spam
  • Email Clients
  • VPN
  • Chat / IM
Programming
  • Editors IDEs
  • Installation
  • Handhelds / PDAs
  • Multimedia Programming
  • System / Kernel
  • Algorithms
  • Game
  • Signal Processing
  • Project Management
  • Open Source
  • Database
  • Misc
  • Languages
  • Processor Platforms
  • Theory
Web Development
  • Scripting
  • Blogs
  • Web Servers
  • Software
  • Search Engines
  • Web Graphics
  • Images
  • Internet Marketing
  • Images and Photos
  • Components
  • Document Imaging
  • Web Languages/Standards
  • Illustration
  • WebApplications
  • Fonts
  • WebTrends / Stats
  • Authoring
  • Digital Camera Software
  • Miscellaneous
Networking
  • Protocols
  • Apple Networking
  • Network Management
  • Message Queue
  • Application Servers
  • Content Management
  • File Servers
  • Email Servers
  • Misc
  • Java Editors & IDEs
  • Wireless
  • Networking Hardware
  • Backup / Restore
  • System Utilities
  • ISPs & Hosting
  • Web Servers
  • Storage Technology
  • Removable Backup Media
  • Servers
  • Broadband
  • Grid
  • OS / 2
  • Novell Netware
  • Unix Networking
  • Windows Networking
  • Security
  • Telecommunications
  • Operating Systems
  • Linux Networking
Other
  • Community Advisor
  • Lounge
  • Community Support
  • New Net Users
  • Philosophy / Religion
  • Math / Science
  • Miscellaneous
  • URLs
  • Expert Lounge
  • Politics
  • Puzzles / Riddles
Community Support
  • Suggestions
  • New to EE
  • New Topics
  • Community Advisor
  • CleanUp
  • Announcements
  • General
  • Feedback
  • Input
  • EE Bugs
 
05.06.2008 at 10:07PM PDT, ID: 21513295

Rank: Genius

DHCP has nothing to do with preventing and securing your Domain..,..

you can lock down shares and files server access via NTFS and Share permissions on your shares - you can also look at playing with ipsec policies to secure your domain pretty heavily - but that gets complex

your most simple solution is NTFS permissions on shares
 
05.06.2008 at 10:08PM PDT, ID: 21513298
Computers should only be able to join the domain if they supply a domain admin password, so that shouldn't be hard to control.  as far as network access, there are lots of options.  The PCI complicance board suggests deactivating network jacks that are not in use.  If you have a managed switch you could configure it so the unused ports are in a different vlan without access.  some switches and firewalls can be set up to check active directory and authenticate machines or users.  DHCP could be used as well, you could create reservations for all the known computers and block unknown machines.
How many network ports are you dealing with...that are available to be misused or whatever?
 
05.06.2008 at 10:11PM PDT, ID: 21513309

Rank: Genius

""Computers should only be able to join the domain if they supply a domain admin password""

not right, any user can add up to 10 computers to the domain

you cannot block unknown machine without some serious DHCP hacks
 
05.06.2008 at 10:17PM PDT, ID: 21513325
The only way you could prevent network access would be if you had a product like ISA server which you could setup to prevent network access unless properly authenticated. (it also depends on what you mean by network access; lan access or internet access or both ? )
This is quite a complex scenario not really suitable for a small network.
If you still want to know more let us know.
 
05.06.2008 at 10:25PM PDT, ID: 21513351
i mean if you are going for a tight domain you should have to have a domain admin password to join a domain.  if you never changed that:
on any DC, go to the Administrative Tools menu and open the Domain Security Policy console. Under Security Settings/Local Policies/User Rights Assignment, you'll see "Add workstations to domain" - set the rights to this so that only Domain Admins can do it.
If you set up DHCP with reservations for all known computers and no range that is outside the reservation list, then a new, unknown computer would not get an address.  Could a savvy user still set a static ip and get access, yes, but avg joe wouldn't be on it.  The feasability of this depends on the number of machines we are talking about here.  
 
05.06.2008 at 10:28PM PDT, ID: 21513358

Rank: Genius

ah agreed, that policy should deffinitely turned on :)

There is some pretty cool tools coming from MS regarding all this security - Network Protection tools that are going to make life a whooole load easier - but at a price
 
05.06.2008 at 10:48PM PDT, ID: 21513419
firstly define "network" access
you could attack this from a network context and use in cisco terms Network Admission Control
This will heavily depend on your networking hardware, if your hardware has the smarts it can
be configured to check whether a given system is allowed network service or not.
if not then prevent it from gaining network access.  The DHCP "static" reservations kinda works, but its major let down is that any body could just configure thier machine with a valid ip address in range and get network access.
 
05.07.2008 at 06:35AM PDT, ID: 21516210
Thanks a lot for all your comments. I think I'm going to learn more about setting up and configuring the ISA Server to properly authenticate the computers or users. By network access, I am referring to my local area network.
 
 
20080236-EE-VQP-29 / EE_QW_2_20070628