Domain auth before issuing IP address via DHCP
Posted on 2011-03-21
I'm trying to see if it's possible to lock down DHCP (running on a Windows 2003 Server R2) so that before a DHCP lease is issued, the computer has to be a member of the domain. I've seen a few posts on EE and on the interweb at large that mention 802.1x and a RADIUS server, but at the moment we don't have a RADIUS server running (only AD/ LDAP.)
I realize that without being a member of the domain and having the proper rights a rouge machine/ user couldn't access any network resources (easily, anyway), I'd still like to avoid and "visitors" to the company who just jack in from causing havoc via malware. (And yes, we do have a guest wifi AP setup on a DMZ, it's just sometimes people see a port and plug in.)
Any thoughts or answers are greatly appreciated on the issue.