Security Policy involving MAC addresses - DHCP required?

Use this forum to post questions relating to WinGate, feature requests, technical or configuration problems

Moderator: Qbik Staff

Security Policy involving MAC addresses - DHCP required?

Postby odge » Nov 30 05 12:02 am

Hi there,

I have a system policy that involves checking if the IP matches the MAC address, because the user is assumed, the IP is correct and MAC address its pretty strong hardware authentication, however, my wingate server is no longer my DHCP server on my new premises. Because of this only pc's that were previously using the wingate server as the DHCP server are able to authenticate, the new pc's that have never used the wingate DHCP server (even though the details are correct) cannot authenticate.

WHY!
odge
 
Posts: 2
Joined: Nov 29 05 11:53 pm

Postby Pascal » Nov 30 05 11:14 am

Because when WinGate leases an IP to a machine it obtains knowledge of it's MAC address. You generally need to use WinGate's DHCP service to have that information available. However, if the client is not a DHCP client of WinGate it will check the ARP cache to see if it can discover the MAC address for it.
Pascal

Qbik New Zealand
pascalv@qbik.com
http://www.qbik.com
Pascal
Qbik Staff
 
Posts: 2623
Joined: Sep 08 03 8:19 pm
Location: Auckland, New Zealand

Postby odge » Nov 30 05 9:33 pm

Hi,

It doesn't seem to be checking the arp cache, in fact it seems to deny the NAT immediately and it doesn't show in the IP arp cache.

I mean, it seems odd to use the DHCP as the check mechanism anyway... because after a pc is turned off, another one could then temporarily use that IP while it is off - meaning you'd still have to check the MAC in real time - meaning that checking the DHCP is a bad idea to begin with, or at least a redundant point.

I hope I'm not being difficult.
odge
 
Posts: 2
Joined: Nov 29 05 11:53 pm


Return to WinGate

Who is online

Users browsing this forum: Bing [Bot], Google [Bot] and 17 guests