Want to win a PS4? Go Premium and enter to win our High-Tech Treats giveaway. Enter to Win

x
?
Solved

Locking down non-domain users /computer

Posted on 2014-03-26
10
Medium Priority
?
694 Views
Last Modified: 2014-04-06
How can I stop non domain joined machines / users  from accessing any files and maybe DNS on an SBS2011 network? (Server 2008 R2)
Considering SBS usually assumes the primary DNS role this would also stop non doamain joined machines from accessing the internet (incliding phones)
Possible?
Any ideas welcome.
Olaf
0
Comment
Question by:Olaf De Ceuster
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
10 Comments
 
LVL 76

Expert Comment

by:Alan Hardisty
ID: 39955561
One way would be to hard-code every domain-joined device on the network and set the DHCP scope to only give out a few IP Addresses which are to things like copiers, but that are reserved addresses, which would basically mean any computer trying to connect and pick up an IP Address would be bang out of luck and wouldn't be able to access the server or the web because they wouldn't have a valid IP Address.

It's not the best / most practical solution on the world, but it would work.
0
 
LVL 22

Author Comment

by:Olaf De Ceuster
ID: 39955589
Hi and thanks  Alan,
Hardcoding is a good idea and easy but how would I stop DHCP from handing out IP's to the other machines? Stop it all together?  How can I then use reservations for printers ect?
And when I need to join a new machine I'd have assing a manual IP?
Thanks
Olaf
0
 
LVL 76

Accepted Solution

by:
Alan Hardisty earned 1000 total points
ID: 39955618
Don't stop DHCP completely - just reduce the scope to only hand out about 3 addresses (or however many printers you have using DHCP at the moment), then make sure you add a reservation for each printer and then DHCP will only hand out IP's to the printers, but the same one every time and there won't be any DHCP addresses left for anything else.

Yes - when you want to add a new machine, you assign it a new fixed IP Address.

It's a pain to manage - but it would solve the problem.

Alternatively, setup the DHCP scope for the number of computers / devices you have and then reserve an IP Address for each device, so that you have DHCP allocating the same IP to each device and then you don't have to write anything down in Excel.  You just expand your scope as you expand your computer base.  That way you have no spare IP's to allocate to un-reserved devices.

Alan
0
Efficient way to get backups off site to Azure

This user guide provides instructions on how to deploy and configure both a StoneFly Scale Out NAS Enterprise Cloud Drive virtual machine and Veeam Cloud Connect in the Microsoft Azure Cloud.

 
LVL 22

Author Comment

by:Olaf De Ceuster
ID: 39955636
Ok I'll give that a go.
Will let you know after the weekend.
Thanks
Olaf
0
 
LVL 22

Author Comment

by:Olaf De Ceuster
ID: 39955637
Can I do Mac Locking like in routers?
Olaf
0
 
LVL 76

Expert Comment

by:Alan Hardisty
ID: 39955643
Yes - you reserve the IP by the MAC address in DHCP.

Shout if you need any help over the weekend.

Alan
0
 
LVL 14

Expert Comment

by:Andy M
ID: 39956030
Regarding stopping access to files on the server, change the share permissions for any folder from Everyone to Authenticated Users (or specific users/groups) - this will force anyone accessing the shares to either be on a domain computer or have to type in username and password for a domain account.

As for stopping DNS access. Well, the first port of call is to find out why you have non-domain systems on the network in the first place. Do you mean staff member phones? If so restricting wireless access will probably be a better way to do this - if they can't even join the wireless they can't do anything.

If it's users hard-wiring their own computers I would look into and discuss this with management as surely this must be against some company policy as effectively they are (without permission) changing system configurations and can cause issues with the network. If users are messing about with network cables they can (even accidentally) knock out the entire network by creating network loops or plugging the wrong cable into a port (speaking from experience with clients who have had similar issues in the past).

Limiting DHCP can help in some cases (though I would put printers on static IP's as well and just remove DHCP altogether) though this can cause issues when you need to update settings in the future (have to manually update each computer).  
Still, if someone with a little bit of knowledge wants to get around this all they have to do is add a static address to their non-domain computer and access will be restored for them.
0
 
LVL 15

Assisted Solution

by:Giovanni Heward
Giovanni Heward earned 1000 total points
ID: 39956260
Look into deploying the Network Policy and Access Services role, which provides for a type of Network Access Control (NAC), called Network Access Protection (NAP).  The enforcement method you'll want to use (or combined with others) is DHCP enforcement.

See http://technet.microsoft.com/en-US/library/dd125379%28v=ws.10%29.aspx

You could also consider deploying a proxy which requires authentication prior to granting Internet access.
0
 
LVL 12

Expert Comment

by:Gary Coltharp
ID: 39958747
If the foreign devices are wireless, either lock it down by changing the security or setup MAC restrictions.

If the foreign devices are wired, a managed switch would work wonders. Just turn off any ports you are not using. Enable them through the web interface when you need to change your infrastructure.

HTH
Gary
0
 
LVL 22

Author Closing Comment

by:Olaf De Ceuster
ID: 39981994
NPA and MAc locking did the trick.
Thanks heaps.
Olaf
0

Featured Post

Free Tool: Path Explorer

An intuitive utility to help find the CSS path to UI elements on a webpage. These paths are used frequently in a variety of front-end development and QA automation tasks.

One of a set of tools we're offering as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Getting to know the threat landscape in which DDoS has evolved, and making the right choice to get ourselves geared up to defend against  DDoS attacks effectively. Get the necessary preparation works done and focus on Doing the First Things Right.
How does someone stay on the right and legal side of the hacking world?
If you're a developer or IT admin, you’re probably tasked with managing multiple websites, servers, applications, and levels of security on a daily basis. While this can be extremely time consuming, it can also be frustrating when systems aren't wor…
We’ve all felt that sense of false security before—locking down external access to a database or component and feeling like we’ve done all we need to do to secure company data. But that feeling is fleeting. Attacks these days can happen in many w…

610 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question