+ Reply to Thread
Results 1 to 11 of 11

Thread: Ipods in DHCP

  Share/Bookmark
  1. #1

    Reputation Reputation Reputation Reputation Reputation Reputation Reputation
    dalsoth's Avatar
    Join Date
    Sep 2008
    Location
    Northants
    Posts
    508
    Thank Post
    172
    Thanked 100 Times in 73 Posts
    Rep Power
    35

    Question Ipods in DHCP

    Not sure if this is the right forum for this q. Anyone know a method to stop students and staff connecting Ipods to the school system? I checked through DHCP addresses today and there were perhaps 30+ Ipod devices with IP addresses and now i am starting to see students personal netbooks appear too along with other mobile phone devices.

    I will not be able to force staff to stop students doing this as the staff are a joke and do not monitor kids in rooms or the library or the post16 area. I know of Packetfence but have never used it. Is this the only solution that is cost free? If so, do i need to add every mac address into Packetfence or are there other ways to get it to block rogue devices? Is packetfence a pain to set up and configure? I do not wish to go static IP so that is not an option with my workload and staff numbers.

    Any advice is appreciated. Thanks.

  2. #2

    Reputation Reputation Reputation Reputation Reputation Reputation Reputation Reputation Reputation Reputation Reputation Reputation Reputation Reputation
    nephilim's Avatar
    Join Date
    Nov 2008
    Location
    Bedfordshire
    Posts
    2,223
    Blog Entries
    1
    Thank Post
    283
    Thanked 287 Times in 231 Posts
    Rep Power
    88

    Default

    switch everyone to static IP addresses, and change your WEP key. If people know it then there is a problem.

  3. #3

    Reputation
    Reputation Reputation Reputation Reputation Reputation Reputation Reputation Reputation Reputation Reputation Reputation Reputation Reputation
    localzuk's Avatar
    Join Date
    Dec 2006
    Location
    Minehead, Somerset
    Posts
    8,384
    Blog Entries
    22
    Thank Post
    264
    Thanked 755 Times in 604 Posts
    Rep Power
    197

    Default

    Security through obscurity will not work (eg. static IP addresses).

    802.1X looks like it would be your friend here. Or at least some form of Mac based filtering (which isn't 100% secure though).

    As these are iPods, i'm guessing they are wirelessly connecting - what wireless system do you have?

  4. #4

    Reputation Reputation Reputation Reputation Reputation Reputation Reputation
    dalsoth's Avatar
    Join Date
    Sep 2008
    Location
    Northants
    Posts
    508
    Thank Post
    172
    Thanked 100 Times in 73 Posts
    Rep Power
    35

    Default

    We have a Trapeze Radius set up and we do not have a default gateway published through DHCP either. Students are not even given a guest pass for the wireless as i do not want them connecting to our system with any non school device.

    We have an ISA that only accepts http through our proxy servers. I doubt they are actually getting on the internet with them but perhaps they are plugging them into computers which is pulling a DHCP address from the server. I do not want loads of Ipods stealing my leases even though they will expire. It is annoying really more than an actual problem.

    As i said in the original post. I do not want to go static ip, was wondering if there were another solution. I will obviously look at Packetfence but at this rate i will end up with a hundred servers doing different things and no time to update and manage them all.

    Thanks for the replies.

  5. #5

    Reputation Reputation Reputation Reputation Reputation Reputation Reputation Reputation Reputation Reputation Reputation Reputation Reputation
    plexer's Avatar
    Join Date
    Dec 2005
    Location
    Norfolk
    Posts
    6,531
    Thank Post
    139
    Thanked 391 Times in 340 Posts
    Rep Power
    95

  6. 2 Thanks to plexer:

    dalsoth (22-10-2009), Rawdon (17-03-2010)

  7. #6

    Reputation Reputation Reputation
    Iain's Avatar
    Join Date
    Oct 2006
    Location
    Warwickshire
    Posts
    137
    Thank Post
    21
    Thanked 55 Times in 32 Posts
    Rep Power
    17

    Default

    There are a couple of options mentioned in this thread too: http://www.edugeek.net/forums/securi...ng-network.htm

  8. Thanks to Iain from:

    dalsoth (22-10-2009)

  9. #7

    Reputation Reputation Reputation
    sidewinder's Avatar
    Join Date
    Jul 2006
    Location
    Near Reading
    Posts
    2,055
    Thank Post
    58
    Thanked 68 Times in 50 Posts
    Rep Power
    22

    Default

    We're getting this too - we have Aruba wireless, no-one can connect without being a member of a specified domain security group and having a certificate installed on the PC....except that is, for ipods and macs, the cert seems to auto install for them when they try and connect, and they can then get internet access. Really annoying

  10. #8

    Reputation Reputation Reputation Reputation Reputation Reputation Reputation
    dalsoth's Avatar
    Join Date
    Sep 2008
    Location
    Northants
    Posts
    508
    Thank Post
    172
    Thanked 100 Times in 73 Posts
    Rep Power
    35

    Default

    Have tried that DLL thing linked above on the server to block certain macs. I do not want the hassle of adding everything to an allow list so i have just picked the macs from DHCP and added them to a deny using that dll and text file from that page. Restarted DHCP and i can see from the text log that the ones i specified are being denied. I hope this is actually working. Time will tell. Thanks for the linkys guys.

  11. #9

    Reputation Reputation Reputation Reputation Reputation Reputation Reputation Reputation Reputation Reputation Reputation Reputation Reputation
    plexer's Avatar
    Join Date
    Dec 2005
    Location
    Norfolk
    Posts
    6,531
    Thank Post
    139
    Thanked 391 Times in 340 Posts
    Rep Power
    95

    Default

    Just use the deny setting then all you have to add is the macs of the devices you wish to deny.

    Ben

  12. Thanks to plexer from:

    dalsoth (22-10-2009)

  13. #10

    Reputation Reputation Reputation Reputation Reputation Reputation Reputation Reputation
    enjay's Avatar
    Join Date
    Apr 2007
    Location
    Reading, Berkshire
    Posts
    2,746
    Thank Post
    147
    Thanked 127 Times in 105 Posts
    Rep Power
    43

    Default

    A free but not fool-proof option is to add all unused IPs to an exclusion range. This will prevent devices getting numbers from DHCP, but won't stop them if they happen to pick a valid unused one and add it manually, so it isn't perfect but it does at least stop the casual attempts.

  14. Thanks to enjay from:

    dalsoth (22-10-2009)

  15. #11

    Reputation

    Join Date
    Mar 2007
    Posts
    329
    Thank Post
    10
    Thanked 13 Times in 7 Posts
    Rep Power
    9

    Default

    I got sick of this as well and spent a little time putting mac filters on our ruckus system

    A bit of work, but surprisingly less devices used the wireless than I thought. Bit of a pain keeping it up to date but you have a better idea of whats using your wireless then.

+ Reply to Thread

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

     

Similar Threads

  1. Without any DHCP
    By siuko in forum O/S Deployment
    Replies: 17
    Last Post: 24-10-2009, 08:05 PM
  2. dhcp
    By kevin_lane in forum Windows
    Replies: 19
    Last Post: 24-09-2008, 09:39 AM
  3. DHCP Help
    By scottyses in forum Windows
    Replies: 7
    Last Post: 07-02-2008, 03:02 PM
  4. dhcp??
    By mac_shinobi in forum Windows
    Replies: 4
    Last Post: 11-01-2008, 01:58 PM
  5. DHCP
    By kingswood in forum Networks
    Replies: 10
    Last Post: 07-09-2005, 06:29 AM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts