Welcome, Register for free! or Login below:
EduGeek.net RSS Feeds Register FAQ Members Social Groups User Map Calendar Search Today's Posts Mark Forums Read

Windows

Windows forum sponsored by

For all of your Windows problems

Go Back   EduGeek.net Forums > Technical > Windows
Reply
 
LinkBack Thread Tools Search Thread
Sponsored Links
Old 22-10-2009, 09:27 AM   #1
 
dalsoth's Avatar
 
Join Date: Sep 2008
Location: Beds
Posts: 498
uk
Thanks: 164
Thanked 100 Times in 73 Posts
Rep Power: 32 dalsoth is a splendid one to behold dalsoth is a splendid one to behold dalsoth is a splendid one to behold dalsoth is a splendid one to behold dalsoth is a splendid one to behold dalsoth is a splendid one to behold dalsoth is a splendid one to behold
Question Ipods in DHCP

Not sure if this is the right forum for this q. Anyone know a method to stop students and staff connecting Ipods to the school system? I checked through DHCP addresses today and there were perhaps 30+ Ipod devices with IP addresses and now i am starting to see students personal netbooks appear too along with other mobile phone devices.

I will not be able to force staff to stop students doing this as the staff are a joke and do not monitor kids in rooms or the library or the post16 area. I know of Packetfence but have never used it. Is this the only solution that is cost free? If so, do i need to add every mac address into Packetfence or are there other ways to get it to block rogue devices? Is packetfence a pain to set up and configure? I do not wish to go static IP so that is not an option with my workload and staff numbers.

Any advice is appreciated. Thanks.
  Reply With Quote
Old 22-10-2009, 09:29 AM   #2
 
nephilim's Avatar
 
Join Date: Nov 2008
Location: Bedfordshire
Posts: 1,195
germany uk bedfordshire
Thanks: 150
Thanked 189 Times in 142 Posts
Blog Entries: 1
Rep Power: 37 nephilim is a splendid one to behold nephilim is a splendid one to behold nephilim is a splendid one to behold nephilim is a splendid one to behold nephilim is a splendid one to behold nephilim is a splendid one to behold nephilim is a splendid one to behold nephilim is a splendid one to behold
Default

switch everyone to static IP addresses, and change your WEP key. If people know it then there is a problem.
  Reply With Quote
Old 22-10-2009, 09:30 AM   #3
 
localzuk's Avatar
 
Join Date: Dec 2006
Location: Minehead, Somerset
Posts: 6,636
isle of man uk isle of man
Thanks: 180
Thanked 490 Times in 400 Posts
Blog Entries: 14
Rep Power: 135 localzuk ooh
localzuk ooh localzuk ooh localzuk ooh localzuk ooh localzuk ooh
Send a message via MSN to localzuk Send a message via Yahoo to localzuk Send a message via Skype™ to localzuk
Default

Security through obscurity will not work (eg. static IP addresses).

802.1X looks like it would be your friend here. Or at least some form of Mac based filtering (which isn't 100% secure though).

As these are iPods, i'm guessing they are wirelessly connecting - what wireless system do you have?
  Reply With Quote
Old 22-10-2009, 09:39 AM   #4
 
dalsoth's Avatar
 
Join Date: Sep 2008
Location: Beds
Posts: 498
uk
Thanks: 164
Thanked 100 Times in 73 Posts
Rep Power: 32 dalsoth is a splendid one to behold dalsoth is a splendid one to behold dalsoth is a splendid one to behold dalsoth is a splendid one to behold dalsoth is a splendid one to behold dalsoth is a splendid one to behold dalsoth is a splendid one to behold
Default

We have a Trapeze Radius set up and we do not have a default gateway published through DHCP either. Students are not even given a guest pass for the wireless as i do not want them connecting to our system with any non school device.

We have an ISA that only accepts http through our proxy servers. I doubt they are actually getting on the internet with them but perhaps they are plugging them into computers which is pulling a DHCP address from the server. I do not want loads of Ipods stealing my leases even though they will expire. It is annoying really more than an actual problem.

As i said in the original post. I do not want to go static ip, was wondering if there were another solution. I will obviously look at Packetfence but at this rate i will end up with a hundred servers doing different things and no time to update and manage them all.

Thanks for the replies.
  Reply With Quote
Old 22-10-2009, 09:41 AM   #5
 
plexer's Avatar
 
Join Date: Dec 2005
Location: Norfolk
Posts: 6,048
uk
Thanks: 102
Thanked 349 Times in 304 Posts
Rep Power: 84 plexer has a brilliant future plexer has a brilliant future plexer has a brilliant future plexer has a brilliant future plexer has a brilliant future plexer has a brilliant future plexer has a brilliant future plexer has a brilliant future plexer has a brilliant future plexer has a brilliant future plexer has a brilliant future plexer has a brilliant future
Default

Microsoft Windows DHCP Team Blog : DHCP Server Callout DLL for MAC Address based filtering

Try that.
  Reply With Quote
Thanks to plexer from:
dalsoth (22-10-2009)
Old 22-10-2009, 09:52 AM   #6
 
Iain's Avatar
 
Join Date: Oct 2006
Location: Warwickshire
Posts: 124
uk
Thanks: 13
Thanked 49 Times in 26 Posts
Rep Power: 15 Iain has a spectacular aura about Iain has a spectacular aura about Iain has a spectacular aura about
Default

There are a couple of options mentioned in this thread too: http://www.edugeek.net/forums/securi...ng-network.htm
  Reply With Quote
Thanks to Iain from:
dalsoth (22-10-2009)
Old 22-10-2009, 10:02 AM   #7
 
sidewinder's Avatar
 
Join Date: Jul 2006
Location: Near Reading
Posts: 1,688
uk
Thanks: 36
Thanked 31 Times in 28 Posts
Rep Power: 15 sidewinder will become famous soon enough sidewinder will become famous soon enough
Default

We're getting this too - we have Aruba wireless, no-one can connect without being a member of a specified domain security group and having a certificate installed on the PC....except that is, for ipods and macs, the cert seems to auto install for them when they try and connect, and they can then get internet access. Really annoying
  Reply With Quote
Old 22-10-2009, 11:42 AM   #8
 
dalsoth's Avatar
 
Join Date: Sep 2008
Location: Beds
Posts: 498
uk
Thanks: 164
Thanked 100 Times in 73 Posts
Rep Power: 32 dalsoth is a splendid one to behold dalsoth is a splendid one to behold dalsoth is a splendid one to behold dalsoth is a splendid one to behold dalsoth is a splendid one to behold dalsoth is a splendid one to behold dalsoth is a splendid one to behold
Default

Have tried that DLL thing linked above on the server to block certain macs. I do not want the hassle of adding everything to an allow list so i have just picked the macs from DHCP and added them to a deny using that dll and text file from that page. Restarted DHCP and i can see from the text log that the ones i specified are being denied. I hope this is actually working. Time will tell. Thanks for the linkys guys.
  Reply With Quote
Old 22-10-2009, 02:01 PM   #9
 
plexer's Avatar
 
Join Date: Dec 2005
Location: Norfolk
Posts: 6,048
uk
Thanks: 102
Thanked 349 Times in 304 Posts
Rep Power: 84 plexer has a brilliant future plexer has a brilliant future plexer has a brilliant future plexer has a brilliant future plexer has a brilliant future plexer has a brilliant future plexer has a brilliant future plexer has a brilliant future plexer has a brilliant future plexer has a brilliant future plexer has a brilliant future plexer has a brilliant future
Default

Just use the deny setting then all you have to add is the macs of the devices you wish to deny.

Ben
  Reply With Quote
Thanks to plexer from:
dalsoth (22-10-2009)
Old 22-10-2009, 02:24 PM   #10
 
enjay's Avatar
 
Join Date: Apr 2007
Location: Reading, Berkshire
Posts: 2,171
uk
Thanks: 108
Thanked 85 Times in 71 Posts
Rep Power: 28 enjay is a glorious beacon of light enjay is a glorious beacon of light enjay is a glorious beacon of light enjay is a glorious beacon of light enjay is a glorious beacon of light enjay is a glorious beacon of light
Default

A free but not fool-proof option is to add all unused IPs to an exclusion range. This will prevent devices getting numbers from DHCP, but won't stop them if they happen to pick a valid unused one and add it manually, so it isn't perfect but it does at least stop the casual attempts.
  Reply With Quote
Thanks to enjay from:
dalsoth (22-10-2009)
Old 23-10-2009, 03:03 PM   #11
 
GoldenWonder's Avatar
 
Join Date: Mar 2007
Posts: 181
uk
Thanks: 5
Thanked 3 Times in 3 Posts
Rep Power: 6 GoldenWonder is on a distinguished road
Default

I got sick of this as well and spent a little time putting mac filters on our ruckus system

A bit of work, but surprisingly less devices used the wireless than I thought. Bit of a pain keeping it up to date but you have a better idea of whats using your wireless then.
  Reply With Quote
Reply

EduGeek.net Forums > Technical > Windows

Similar Threads
Thread Thread Starter Forum Replies Last Post
[Fog] Without any DHCP siuko O/S Deployment 17 24-10-2009 08:05 PM
dhcp kevin_lane Windows 19 24-09-2008 09:39 AM
DHCP Help scottyses Windows 7 07-02-2008 04:02 PM
dhcp?? mac_shinobi Windows 4 11-01-2008 02:58 PM
DHCP kingswood Networks 10 07-09-2005 06:29 AM



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools Search Thread
Search Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT +1. The time now is 07:44 PM.
Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.3.2 ©2009, Crawlability, Inc.
Copyright EduGeek.net




website uptime

© 2005 - 2009 EduGeek.net
SERVER: 4
no new posts