Re: Blocking access to network via IP/MAC/dhcpd?

This is a discussion on Re: Blocking access to network via IP/MAC/dhcpd? within the IPFilter forums, part of the System Security and Security Related category; On 2007-11-26 00:33, Amadeus wrote: > I could force a MAC address to use a specific IP ...


Go Back   Usenet Forums > System Security and Security Related > IPFilter

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 11-26-2007
Jefferson Ogata
 
Posts: n/a
Default Re: Blocking access to network via IP/MAC/dhcpd?

On 2007-11-26 00:33, Amadeus wrote:
> I could force a MAC address to use a specific IP in dhcpd, but again,
> they could just configure their IP manually.


Well, if you *could* be doing this, then you already *should* be doing
this. If you know which systems are supposed to be on your network, it's
only sensible to preallocate the IPs so that when a packet comes along
you know which system it's supposed to be from without having to dig
through the DHCP leases. The data is already there in the leases; just
transfer it to the config.

> Do you have any suggestions for this problem?


Associate fixed IPs with every box in the DHCP config as discussed
above, then assign a static arp entry for every legitimate IP, then
disable native arp.

If your users change MACs, then the firewall won't be able to talk to
them. The weakness is then that if a box is offline, they can borrow its
MAC and IP combination, if they know it.

The catch is I'm not sure whether you can disable native arp on NetBSD.
If not, you could use arpwatch to trigger a script to blackhole any new
MACs that show up.

Another suggestion: make users sign an acceptable use policy in exchange
for access, and report violators to management. Enforceable policy is
always an effective alternative where technical methods fail.

Or there's always IPsec.

Or what Darren said.

--
Jefferson Ogata <Jefferson.Ogata@noaa.gov>
NOAA Computer Incident Response Team (N-CIRT) <ncirt@noaa.gov>
"Never try to retrieve anything from a bear."--National Park Service
Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT +1. The time now is 10:52 AM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0