Link to home
Start Free TrialLog in
Avatar of Marka Mekapse
Marka MekapseFlag for United States of America

asked on

dhcp best practices

1st off don't laugh. this is an embarrassment to the IT World

So i just started working at this company and man i have to say their network is jacked up.

they have 2 DHCP scopes running on two different servers

the DHCP scope has no reservation allocated for the networking gear or the servers

their servers have 2 active nics (some 3) on the same network - no sub-netting.  

they have a slew of ip-conflicts weekly (attributed by the servers being in the same pool as the dhcp scope)

What i would like to know is this
1. by removing the homing nics will it increase performance?
2. how is this setup bad?  

sorry just ranting and looking for good answers
ASKER CERTIFIED SOLUTION
Avatar of InteraX
InteraX
Flag of United Kingdom of Great Britain and Northern Ireland image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of Marka Mekapse

ASKER

i was looking for a more constructive way to tell the client that there was something wrong with the current setup.  you gave a great answer but i indicated that i knew the answer.

thanks anyway
As for a more constructive way to tell the client they have a bad setup, tell them that are expeirncing porblems and issues right now. Until this is sorted out, they will cary on experiencing problems.

If they want to see MS best practices, see http://technet.microsoft.com/en-us/library/cc780311(WS.10).aspx & http://technet.microsoft.com/en-us/library/cc776596(WS.10).aspx

One thing MS haven't included on their DHCP server is DHCP server clustering which is now in the spec, but MS want you to buy their enterprise version of Windows and cluster DHCP using windows clustering. 3 times the cost.
hi guys


i appreciate the feedback, this PIX seems to have some sort of issue outside of the configuration.  the only thing i did outside of the config was upgrade the firewall pdm software.  The other line items regarding http .0.0.0.0 and telnet 0.0.0.0  :)  i was unable to hit the pdm from the outside (assuming i could use telnet on ethernet0 - and that we must use SSH on the public interface.)  

so once i get everything cleared up, i will remove these and take care of everything internally from one of the servers using rdp.

i really appreciate the feedback.

i did notice that each time i put a command in place it takes the firewall several minutes to "turn on" or "turn off" ... i.e. i add a NAT rule and it is inaccessible for several minutes.  i know the device is old but i am using this in the interim until i can get myself a decent ASA 5505
lol - disregard my last post intended for another issue

thanks for your feedback :)