Jump to content

emboha

Members
  • Posts

    23
  • Joined

  • Last visited

Reputation

0 Neutral

About emboha

  1. thought so. I contacted my hardware retailer for some advice. Waiting for them to call me back. thx
  2. So connecting the server directly to the router and assigning 84.197.19.170 to 1 NIC adapter and assigning 192.168.1.1 to another nic in the same server and setting up a dhcp scope from 192.168.1.10-254 wouldn't do the trick? Is a firewall always needed in my case?
  3. I need some help 1) new internet connection is active and router is installed and configured with a tiny scope of 8 fixed ip adresses, 1 being the router itself. For example 84.197.19.169 for the router 84.197.19.170-177 free to use With a 255.255.255.248 subnet 2) no access to the router at all (telenet router with remote config by the isp itself) 3)i have 1 windows server 2012 machine which i want to use as dhcp and dns server. 4)i have 1 dlink manageable core switch which sits between router and server. 5) question: What fixed ip should i give the switch? What fixed ip should i give the server? And if i give the server one of the fixed ip-adresses from isp it will be outside the subnet from its own dhcp scope it is providing to the internal network (for example 192.168.1.0-254) thus be unreachable for all the clients?
  4. I've added the topology for anyone who is curious :-)
  5. I guess I can tackle the 2nd problem (too few ip adresses) easily by 1. Shortening the dhcp lease time 2. Enabling mac filtering so students cant receive a dynamic ip when they somehow got the wifi password. There is currently no budget for an audit by an external firm, I allready made a complete network topology and its a horrific train network. Something i ll need to deal with later too. The whole network needs to be reshaped and next year they are destroying 2 old center buildings, so i guess that will be the appropriate time to get those things done. My ISP is also pointing me to an external network audit firm because they know of the network complexity on our site.
  6. The router is managed by my ISP. I only have a "user" password where i can only change the wifi password etc. None of the important stuff. Its a technicolor TG670. Which by the way is another problem: We are reaching our 255 internal IPadress limit of my current 255.255.255.0 subnet mask. I can't even resubnet to 255.255.252.0 for example, because the router won't let me change it's subnetmask. But maybe that's for another topic ;-)
  7. Guys I've searched the interweb for help on setting up a VLAN to separate our AP's from the network, so they only can use the internet but can not connect to our internal network. But it's still all a bit unclear for me. This is my situation: - Only 1 single link (port connected) between all the switches. - Only 1 subnet on the network: 192.168.1.x - 192.168.1.253: DHCP-server - 192.168.1.254: router - 192.168.1.248: main switch: DLINK DGS 1500-28 - Fixed IPadresses for all the other switches (DLINK easysmart family line) and AP's (cheap sitecom AP's) The ports indicated are used to connect the devices with eachother. With my setup: is it even possible what I am trying to do? does my AP have to support VLAN or can i just isolate the port going from the smart switch to the AP? If yes: Is it enough to create 1 additional VLAN on each of the switches (02 Wifi), there is allready a default one (1) with alle the ports untagged on each switch. What is the status of the ports (tagged/untagged/not member) on the 02 Wifi VLAN on the main switch? => I think its P4 tagged, the rest untagged? What is the status of the ports (tagged/untagged/not member) on the 02 Wifi VLAN on the second switch DGS 1100-8? => I think its P1 and P8 tagged, the rest untagged or also P2 tagged? What is the status of the ports (tagged/untagged/not member) on the 02 Wifi VLAN on the third switch DGS 1100-8? =>I think its P1 and P8 tagged, the rest untagged? Do I have to also tag the port of the DHCP server or router in the 02 Wifi VLAN on the main switch? thx in advance
  8. had this happen on our network too, Never found the bugger, but when I visited the ipadres of the server from an "affected" client pc, i was greeted by a login page of conceptronic (the brand of the rogue dhcp server) I finally made it stop by only allowing the right dhcp server in the settings of our manageable switch. I believe this was the setting: Trusted DHCP Server IP Lists
  9. not completely sure what u mean by that, Rob No laptops get weird IP-adresses anymore now, so it seems to me the problem is indeed fixed? U mean that the rogue machine is still on my network somewhere? Can be, but i seems it isn't able anymore to act as a dhcp server...?
  10. Ok, this seems to have fixed the problem permanently. In my manageable switch at the beginning of my network i adjusted the following settings: Security/DHCP Server Trusted Port Settings: all disabled except the 2 ports which are used for the server. Security/Trusted DHCP Server IP Settings: added the internal IP-adress of my dhcp server (win2012 standard machine) No rogue dhcp server should be able to be active on my network anymore now... Still find it odd tho, that U have to block such a thing...
  11. Today I used my manageable switch to add the ip of a trusted dhcp server (my win2012 server) and blocked all the ports on my switch (except the one(s) of my server) to allow dhcp. I hope this helps, we wil see...
  12. the problem returned today, i again changed the password and the settings... solved again, but for how long? my switch: DGS-1500-28: 28-Port Gigabit SmartPro Switch including 4 SFP ports (fanless) from DLINK Can i get the info with that switch even if the device isnt directly connected to it but through a couple of other regular switches?
  13. The name is SKYNET_BE, and it is not on my server's dhcp list, not by that name, and not by that mac adress. I'll walk around the building tomorrow with the wifi analyser tool and search for that SSID. I'll keep u guys posted, thx for all the help allready ;-)
  14. Can you track which port it's connected to on your switches ? => I'll check tomorrow. It's the first time I will use a manageable switch tho, can't be hard ;-) my win2012 server only gives out ip adresses in the range i want it to so i don't think it gives an adress to the rogue device... I can't find it in the list of leases anyhow...
  15. idd, it's a company that doesn't exist anymore. I've changed all the AP's passwords yesterday and still today, it gave me problems, so i'm guessing its connected to my wired network somewhere? I'm guessing, tomorrow will be problematic again, cause to my knowledge, my AP's are secure a.t.m. with the new password (and still it was connected today). I've disabled it's dhcp-server option again and all is fine at the moment.
×
×
  • Create New...