Greetings,
is it possible for wingate to lock the asumed users to their MAC address in addition to the IP address, an option for which is already provided under user assumptions?
my setup uses Wingate DHCP to allocate IPs to users using MAC reservations, so every adapter on the network has a unique ID according to its physical location. the IP address is then binded to a username using asumptions. now at times i wish to block access by some users, i simply disable the user and the user is unable to access the wingate services. now there are a few malicious users who change their IP when blocked, to any other unblocked available IP and continue the usage without the wingate server knowing their true identity, i as the admin notice the illeagal IP hijacking through their behaviour and traffic usage. i also wish to point out that i do not wis to use Wingate Authentication as this would make the process rather complicated for certain users.
my solution was to install a stateful packet inspection firewall, with an option for MAC address filtering(which was very difficult to find-i know of only 3 products which are capable of this(8igns firewall, Visnetic Firewall and Sygate Personal Firewall PRO version 5.x), if you ahve any recomendations i would be more than glad to try them out!), by this i can block the MAC address of the computers i do not wish to have access to the Wingate machine, upon implementation of this strategy, sure enough, the malicious users gave up changing their IPs. as they were deined ALL access tot he wingate machine, which was fine with me, and the network ran in relative harmony, but the firewall created complications and excessive CPU usage ont he WIngate machine. this created a problem for me!
now my question/request : is there some way in wingate to make sure a certain IP address is only used by a certain MAC address, where the users are assumed by IP address which has been assigned to a specific MAC address by method of IP reservation using Wingate's DHCP server?
i hope i was clear in putting my question/problem across to you.
thank yoy very much in advance for your time and effort.
best regards,
Shayan
P.S.
i would also appriciate it if a solution for the so called Phantom Adapter Problem can be published too. if at all the problem i have been facing from the past 2 weeks can be called that!...upon disconnecion and reconnection of a dialup connection, wingate server is unable to detect the connection/stream any data to/from the internet to/from the clients. the wingate service has to be shut down, connection disconnected, manually reconnected using windows dial up networking, and service restarted for it to work again. upon disconnection the same thing happens. even when the wingate's internal dialer is used. i would appriciate it if you could acknowledge the refrence to my problem.
i am using Win2kProSP4 with all latest patches.
Please also note that i have been forced to disable ALL ENS functionality under wingate because some Windows 2000 patch causes the ENS plugin to cause Wingate.exe to chew up all available physical and virtual memory and bring the machine to a crashing almost half of a crawl!! since i am using a strict proxy based setup, this is not much of a bother to me, but i thought id let you know anyway.but certain java applets do require me to enable some ports on the NAT system, or if you can tell me how to open port 5000 for Vectracom's SMS sending Java applet or allow me to open ports 6891 to 6900 and also open ports needed for Yahoo Online Games applets to load, i would forever remain grateful to you. this i want WITHOUT using NAT...i believe the proxy based setup to be more loggable and controlable than the NAT solution.