• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 426
  • Last Modified:

Assign a dhcp address pool to a group of windows desktops

I am working on testing virtual desktops in our environment. One gotcha that I have come up with is the assignment of IP addresses to the virtual desktops that are created. In our current environment we use dhcp reservations to assign IP addresses to our desktops. The main reason for this is security.

However, now the virtual desktops are causing me a problem. I can assign IP addresses to the desktops via dhcp. However the virtual desktops are non-persistent so I lose the ability to do reservations since you don't know what the MAC address for the desktop will be as they are created.

If we're going to implement virtual desktops I have to have another solution to provide the security that DHCP reservations provide. At this point I'm at a loss on what possible solutions are out there. I've thought about NAC but I'm unfamiliar with it's capabilities (plus there's the cost involved). I also wondered if there's a way assign a pool of IP addresses to a specific AD group of machines.

Thanks.
0
snowmizer
Asked:
snowmizer
  • 3
  • 2
2 Solutions
 
DeojiCommented:
Put your Virtual Network on it's own VLAN then allow DHCP to assign dynamically to that VLAN.
As long as you don't assign any ports on switches to that VLAN that people could patch into then you should be safe, in fact safer than the way you are doing it because all someone needs to do now is manually assign a static IP in the range of what your DHCP has as reserved and as long as it isn't in use they should be able to access the network.
0
 
snowmizerAuthor Commented:
You're talking about setting up a vlan on my physical switches or just my virtual switches. Right now I don't have vlans on my physical switches because I will have to modify every switch in the building (future weekend project :)).
0
 
DeojiCommented:
You could do it just on your virtual switches but you have to have a way on your virtual switches to have a DHCP helper address or you whould need a seperate DHCP server on that VLAN. Also you need to allow Routing between the New VLAN and our networks that you need to access.
0
 
snowmizerAuthor Commented:
Hummmm, that's an intriguing option. Unfortunately I don't have much (or any) experience with VLANs in the virtual environment. So basically what you're saying is as follows:

1. Create a virtual switch that has all used ports assigned to a vlan.
2. Setup a virtual dhcp server that is setup on this virtual switch. The dhcp server will provide ip addresses in a different subnet.
3. Set up routing from this subnet to the server subnet (which will require a physical router or can this be done virtually as well).
0
 
DeojiCommented:
Yep, that's it in a nut-shell.
0

Featured Post

Put Machine Learning to Work--Protect Your Clients

Machine learning means Smarter Cybersecurity™ Solutions.
As technology continues to advance, managing and analyzing massive data sets just can’t be accomplished by humans alone. It requires huge amounts of memory and storage, as well as the high-speed power of the cloud.

  • 3
  • 2
Tackle projects and never again get stuck behind a technical roadblock.
Join Now