Security Basics mailing list archives

Re: prohibiting visitors from connecting to network


From: "Terence Summers" <tsummers () infosecuritylab com>
Date: Tue, 25 Oct 2005 13:06:53 +0200

In terms of network security MAC filtering makes almost no sense. Even basic routers and network cards can modify their MAC addresses. There are effective hacker tools to attack networks with only this kind of protection.

Terence
infosecuritylabs.com

Why not limit DHCP to known MAC addresses. The administrative costs of this
might be pretty high at first, but you could eventually work out an
automated system for adding/removing machines. That's the only "free" option
that I can think of.

Even then, though, I believe you can spoof MAC addresses so...

-----Original Message-----
From: Alexander Suhovey [mailto:asuhovey () mtu-net ru]
Sent: Thursday, October 20, 2005 2:01 PM
To: 'Cesar Diaz'; security-basics () securityfocus com
Subject: RE: prohibiting visitors from connecting to network

> What I'm looking for is a way to secure DHCP so that only our
> laptops/workstations can get a DHCP address.
> I was thinking of something like EAP used for remote access with
> certificates to keep computers without a certificate from
receiving an
> IP address, but I can find any information on implementing this.




Current thread: