Solved

DHCP setup on Watchguard Firebox and not on W2K Server???

Posted on 2003-11-16
5
2,049 Views
Last Modified: 2013-12-19
I just inherited the IT jobs for my company and have some basic questions.

1.  The current config is one W2K server with a Watchguard Firebox and a net gear hub.  30 Clients all using XP Pro or WIN 2000.  The last guy set up the DHCP on the Firebox and not the W2K server.  Should I make the W2K server the DCHP server or keep it the way it is?  The XP machines take a long time to log in (just fixed the DNS root problem).  Is this current setup a security issue?

2.  Does anyone have any experience with the firebox?

Thanks.

jon
0
Comment
Question by:stewartje
  • 2
  • 2
5 Comments
 
LVL 79

Expert Comment

by:lrmoore
ID: 9762776
There's an old saying - If it ain't broke, don't fix it...
However, if your Watchguard is providing DHCP and you are having name resolution issues, then it is most likely DNS that is not properly set up rather than DHCP. Plus, I don't think that the Watchguard's DHCP is telling the clients to register themselves in DNS. In this case, it IS broke. Moving DHCP to the Windows server certainly will give you that option.
Is it a security issue to keep it on the firewall? My philosopy is to let the firewall do what it does best - block bad packets coming in. Don't put any extra burden on it for trivial services that can be done by another system.

I'm a PIX guy myself, but if you have specific questions on the firebox, I'm sure there are other experts hanging out here that can help..


0
 
LVL 37

Expert Comment

by:bbao
ID: 9764516
Commonly, W2K DHCP server have more options for DHCPO clients than other firewalls, especially for those AD related settings. Of course, if you dont need those, only need dynamic IP assignment, don't change anything if it works well.
0
 

Author Comment

by:stewartje
ID: 9765027
Thank you and I understand about not fixing things that are working.

I would like to hear from others about the Firebox.

I fixed the DNS problem but am unfamiliar with its workings as well.  It sucks not knowing much about it.  I bought a book by Mark Minasi and am reading it but we have problems that need to be fixed now.  

jon
0
 
LVL 79

Accepted Solution

by:
lrmoore earned 500 total points
ID: 9765625
Here are some good references on DNS

Windows 2000 DNS - Diagnosing Name Resolution Problems
http://www.microsoft.com/windows2000/techinfo/reskit/en-us/cnet/cncf_imp_zvri.asp
FQDN = Fully Qualified Domain Name

Windows 2000 DNS - Solving other common DNS problems
http://www.microsoft.com/windows2000/techinfo/reskit/en-us/cnet/cncf_imp_ibxf.asp

Ping Utility Takes a Long Time to Return Results with NetBIOS Name
http://support.microsoft.com/default.aspx?scid=kb;en-us;267963

NetBIOS over TCP/IP Name Resolution and WINS
http://support.microsoft.com/default.aspx?scid=kb;EN-US;119493

If you have specific questions on the firebox, post them in the Security/firewalls topic area forum.
0
 

Author Comment

by:stewartje
ID: 9765773
Thank you for the links.  I will end this thread and start a new one in the other section.

jon
0

Featured Post

Portable, direct connect server access

The ATEN CV211 connects a laptop directly to any server allowing you instant access to perform data maintenance and local operations, for quick troubleshooting, updating, service and repair.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Sometimes you might need to configure routing based not only on destination IP address, but also on a combination of destination IP address (or hostname) and destination port number. I will describe a method how to accomplish this with free tools. …
Enterprise networks where VoIP phones have been deployed frequently use port configurations that allow both a computer and an IP phone to be plugged into the same switch port but use different VLANs. On Cisco equipment I'm referring to the "native V…
With Secure Portal Encryption, the recipient is sent a link to their email address directing them to the email laundry delivery page. From there, the recipient will be required to enter a user name and password to enter the page. Once the recipient …

685 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question