Domain auth before issuing IP address via DHCP

Posted on 2011-03-21
Last Modified: 2012-05-11
I'm trying to see if it's possible to lock down DHCP (running on a Windows 2003 Server R2) so that before a DHCP lease is issued, the computer has to be a member of the domain. I've seen a few posts on EE and on the interweb at large that mention 802.1x and a RADIUS server, but at the moment we don't have a RADIUS server running (only AD/ LDAP.)

I realize that without being a member of the domain and having the proper rights a rouge machine/ user couldn't access any network resources (easily, anyway), I'd still like to avoid and "visitors" to the company who just jack in from causing havoc via malware. (And yes, we do have a guest wifi AP setup on a DMZ, it's just sometimes people see a port and plug in.)
Any thoughts or answers are greatly appreciated on the issue.
Question by:biofishfreak
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 3

Expert Comment

ID: 35184613

Check out this article

Wireless networking in Windows Server 2003

Author Comment

ID: 35184670
AD man, would this sort of setup translate to a wired network? The recent issue we've had is a consultant was asked to sign onto our DMZ wireless network, but instead they plugged into our ethernet network. This is what we are trying to avoid right now. It's kind of looking like MAC address filtering is the way to go.

Accepted Solution

ActiveDirectoryman earned 350 total points
ID: 35184921

Yea, there is

here you go :

Deployment of IEEE 802.1X for Wired Networks Using Microsoft Windows
Optimizing Cloud Backup for Low Bandwidth

With cloud storage prices going down a growing number of SMBs start to use it for backup storage. Unfortunately, business data volume rarely fits the average Internet speed. This article provides an overview of main Internet speed challenges and reveals backup best practices.

LVL 46

Assisted Solution

by:Craig Beck
Craig Beck earned 150 total points
ID: 35199208
You can make a RADIUS server using a Windows Server by installing IAS (2003) or NPS (2008).

However, Microsoft are a bit twitchy when it comes to supporting clients using 802.1X.
This would be the way to do it though, and I have deployed this in some big sites without any problems.

Of course, your switches will need to support 802.1X too.

Expert Comment

ID: 35199260

It explains that in the article.  It is very straight-forward.

Author Comment

ID: 35200901
Awesome, thanks you two. I'm going to wait to double check with my network guy on this when he gets back in on Monday. I'll update everyone then.

Author Closing Comment

ID: 35796991
Wow, I suck at responding fast. So after talking with my Network Admin, we've decided to use some network monitoring software to detect when a new system comes onto the network, alert us, and we roll out ASAP to fix things. I appreciate both of your help, and assigned points to the both of you.

Featured Post

Free Tool: ZipGrep

ZipGrep is a utility that can list and search zip (.war, .ear, .jar, etc) archives for text patterns, without the need to extract the archive's contents.

One of a set of tools we're offering as a way to say thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article explains the steps required to use the default Photos screensaver to display branding/corporate images
This article shows the method of using the Resultant Set of Policy Tool to locate Group Policy that applies a particular setting.
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles from a Windows Server 2008 domain controller to a Windows Server 2012 domain controlle…
Microsoft Active Directory, the widely used IT infrastructure, is known for its high risk of credential theft. The best way to test your Active Directory’s vulnerabilities to pass-the-ticket, pass-the-hash, privilege escalation, and malware attacks …

696 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question