Solved

DHCP setup on Watchguard Firebox and not on W2K Server???

Posted on 2003-11-16
5
2,015 Views
Last Modified: 2013-12-19
I just inherited the IT jobs for my company and have some basic questions.

1.  The current config is one W2K server with a Watchguard Firebox and a net gear hub.  30 Clients all using XP Pro or WIN 2000.  The last guy set up the DHCP on the Firebox and not the W2K server.  Should I make the W2K server the DCHP server or keep it the way it is?  The XP machines take a long time to log in (just fixed the DNS root problem).  Is this current setup a security issue?

2.  Does anyone have any experience with the firebox?

Thanks.

jon
0
Comment
Question by:stewartje
  • 2
  • 2
5 Comments
 
LVL 79

Expert Comment

by:lrmoore
Comment Utility
There's an old saying - If it ain't broke, don't fix it...
However, if your Watchguard is providing DHCP and you are having name resolution issues, then it is most likely DNS that is not properly set up rather than DHCP. Plus, I don't think that the Watchguard's DHCP is telling the clients to register themselves in DNS. In this case, it IS broke. Moving DHCP to the Windows server certainly will give you that option.
Is it a security issue to keep it on the firewall? My philosopy is to let the firewall do what it does best - block bad packets coming in. Don't put any extra burden on it for trivial services that can be done by another system.

I'm a PIX guy myself, but if you have specific questions on the firebox, I'm sure there are other experts hanging out here that can help..


0
 
LVL 37

Expert Comment

by:Bing CISM / CISSP
Comment Utility
Commonly, W2K DHCP server have more options for DHCPO clients than other firewalls, especially for those AD related settings. Of course, if you dont need those, only need dynamic IP assignment, don't change anything if it works well.
0
 

Author Comment

by:stewartje
Comment Utility
Thank you and I understand about not fixing things that are working.

I would like to hear from others about the Firebox.

I fixed the DNS problem but am unfamiliar with its workings as well.  It sucks not knowing much about it.  I bought a book by Mark Minasi and am reading it but we have problems that need to be fixed now.  

jon
0
 
LVL 79

Accepted Solution

by:
lrmoore earned 500 total points
Comment Utility
Here are some good references on DNS

Windows 2000 DNS - Diagnosing Name Resolution Problems
http://www.microsoft.com/windows2000/techinfo/reskit/en-us/cnet/cncf_imp_zvri.asp
FQDN = Fully Qualified Domain Name

Windows 2000 DNS - Solving other common DNS problems
http://www.microsoft.com/windows2000/techinfo/reskit/en-us/cnet/cncf_imp_ibxf.asp

Ping Utility Takes a Long Time to Return Results with NetBIOS Name
http://support.microsoft.com/default.aspx?scid=kb;en-us;267963

NetBIOS over TCP/IP Name Resolution and WINS
http://support.microsoft.com/default.aspx?scid=kb;EN-US;119493

If you have specific questions on the firebox, post them in the Security/firewalls topic area forum.
0
 

Author Comment

by:stewartje
Comment Utility
Thank you for the links.  I will end this thread and start a new one in the other section.

jon
0

Featured Post

What Security Threats Are You Missing?

Enhance your security with threat intelligence from the web. Get trending threat insights on hackers, exploits, and suspicious IP addresses delivered to your inbox with our free Cyber Daily.

Join & Write a Comment

Greetings, Experts! First let me state that this website is top notch. I thoroughly enjoy the community that is shared here; those seeking help and those willing to sacrifice their time to help. It is fantastic. I am writing this article at th…
Many of us in IT utilize a combination of roaming profiles and folder redirection to ensure user information carries over from one workstation to another; in my environment, it was to enable virtualization without needing a separate desktop for each…
Internet Business Fax to Email Made Easy - With eFax Corporate (http://www.enterprise.efax.com), you'll receive a dedicated online fax number, which is used the same way as a typical analog fax number. You'll receive secure faxes in your email, fr…
This video gives you a great overview about bandwidth monitoring with SNMP and WMI with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're looking for how to monitor bandwidth using netflow or packet s…

728 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

11 Experts available now in Live!

Get 1:1 Help Now