Configuring DHCP Relays and Scanning for Rogue Mac Addresses

From: Will (DELETE_westes_at_earthbroadcast.com)
Date: 09/26/05


Date: Mon, 26 Sep 2005 10:30:20 -0700

I have client machines on a protected subnet behind a firewall, and a DHCP
server on a separate protected subnet. I need to relay the DHCP client
requests from one subnet to the other, and for security reasons I don't want
a DHCP relay application running on the firewall. Does OpenBSD support a
DHCP relay that would allow a configuration like:

    client on subnet A <----> dhcp relay on subnet A <----> firewall <---->
dhcp relay on subnet B <----> dhcp server

What software supports that configuration?

Some additional features that would be really nice to have:

- Ability to scan for any DHCP request from an unrecognized Mac address,
which would then trigger alerts to either/both syslog and e-mail.

- Ability to scan all ARP requests on the network looking for unrecognized
Mac addresses, the presence of which would trigger alerts.

I want to make it very difficult for a rogue device to get installed on our
network without our having immediate visibility on the fact.

If anyone has other ideas on features we should be looking for in either a
DHCP relay or Mac Address scanner, please feel free to add those.

If the above is available as a commercial device, I would appreciate
references to the vendor's product page as well.

-- 
Will


Relevant Pages

  • Re: XP2-Firewall, DHCP via Relay
    ... Ein XP SP2-Client, auf DHCP gestellt. ... einen Relay Agent erreicht werden kann. ... Wird die Firewall ausgeschaltet, geht alles. ...
    (de.comp.security.firewall)
  • Re: XP2-Firewall, DHCP via Relay
    ... Ein XP SP2-Client, auf DHCP gestellt. ... einen Relay Agent erreicht werden kann. ... Wird die Firewall ausgeschaltet, geht alles. ...
    (de.comp.security.firewall)
  • Re: DHCP Server mit mehreren DHCP Bereichen
    ... DHCP Relay Agenten, so wie Jörg das schon schilderte. ... Der DHCP merkt anhand des Feldes "GIADDR", ... verteilt dadurch auch IPs für andere Subnetze. ... Konfig eh erst mal in einen Netz Testen das mit dem Firmennetzwerk getrennt ...
    (microsoft.public.de.german.windows.server.networking)
  • Re: XP2-Firewall, DHCP via Relay
    ... Ein XP SP2-Client, auf DHCP gestellt. ... einen Relay Agent erreicht werden kann. ... Wird die Firewall ausgeschaltet, geht alles. ...
    (de.comp.security.firewall)
  • Re: Reverse Lookup Zone question
    ... Our Cisco routers have a DHCP relay function - I assumed that's all I needed ... Which domain should the DHCP server belong to? ... You would have to configure a DHCP Relay agent on each ...
    (microsoft.public.win2000.dns)