ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    Concern Around Hackers Using DHCP Pool

    Scheduled Pinned Locked Moved IT Discussion
    56 Posts 8 Posters 2.3k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • JaredBuschJ
      JaredBusch @Dashrender
      last edited by

      @Dashrender said in Concern Around Hackers Using DHCP Pool:

      I will grant you that the attack is extremely unlikely either against DNS or DHCP, but considering it takes seconds to setup, I don't see the harm in it either. Coupled with the already stated fact of the Windows licensing makes it a requirement in my case since I don't want to setup completely separate APs for guest access.

      Takes seconds? You are having nothing but issues because of wanting a VLAN.

      DashrenderD 1 Reply Last reply Reply Quote 2
      • DashrenderD
        Dashrender @JaredBusch
        last edited by

        @JaredBusch said in Concern Around Hackers Using DHCP Pool:

        @Dashrender said in Concern Around Hackers Using DHCP Pool:

        I will grant you that the attack is extremely unlikely either against DNS or DHCP, but considering it takes seconds to setup, I don't see the harm in it either. Coupled with the already stated fact of the Windows licensing makes it a requirement in my case since I don't want to setup completely separate APs for guest access.

        Takes seconds? You are having nothing but issues because of wanting a VLAN.

        Thanks - it's true I have a current issue, that's related to VLANs - but this guest network is not one of them. That was installed and working in only seconds longer than it would have taken if I didn't have a VLAN. my current issues are around a legacy network.

        stacksofplatesS 1 Reply Last reply Reply Quote 0
        • stacksofplatesS
          stacksofplates @Dashrender
          last edited by

          @Dashrender said in Concern Around Hackers Using DHCP Pool:

          @JaredBusch said in Concern Around Hackers Using DHCP Pool:

          @Dashrender said in Concern Around Hackers Using DHCP Pool:

          I will grant you that the attack is extremely unlikely either against DNS or DHCP, but considering it takes seconds to setup, I don't see the harm in it either. Coupled with the already stated fact of the Windows licensing makes it a requirement in my case since I don't want to setup completely separate APs for guest access.

          Takes seconds? You are having nothing but issues because of wanting a VLAN.

          Thanks - it's true I have a current issue, that's related to VLANs - but this guest network is not one of them. That was installed and working in only seconds longer than it would have taken if I didn't have a VLAN. my current issues are around a legacy network.

          https://mangolassi.it/topic/12645/unifi-switch-tagged-traffic-issues

          Wasn't this thread started because you couldn't get it to work?

          DashrenderD 1 Reply Last reply Reply Quote 1
          • scottalanmillerS
            scottalanmiller @Dashrender
            last edited by

            @Dashrender said in Concern Around Hackers Using DHCP Pool:

            I will grant you that the attack is extremely unlikely either against DNS or DHCP, but considering it takes seconds to setup, I don't see the harm in it either. Coupled with the already stated fact of the Windows licensing makes it a requirement in my case since I don't want to setup completely separate APs for guest access.

            If it only took seconds, took nothing to maintain, added no complexity to the network and was just as easy to hand over to someone else, then I'd agree.

            1 Reply Last reply Reply Quote 0
            • DashrenderD
              Dashrender @stacksofplates
              last edited by

              @stacksofplates said in Concern Around Hackers Using DHCP Pool:

              @Dashrender said in Concern Around Hackers Using DHCP Pool:

              @JaredBusch said in Concern Around Hackers Using DHCP Pool:

              @Dashrender said in Concern Around Hackers Using DHCP Pool:

              I will grant you that the attack is extremely unlikely either against DNS or DHCP, but considering it takes seconds to setup, I don't see the harm in it either. Coupled with the already stated fact of the Windows licensing makes it a requirement in my case since I don't want to setup completely separate APs for guest access.

              Takes seconds? You are having nothing but issues because of wanting a VLAN.

              Thanks - it's true I have a current issue, that's related to VLANs - but this guest network is not one of them. That was installed and working in only seconds longer than it would have taken if I didn't have a VLAN. my current issues are around a legacy network.

              https://mangolassi.it/topic/12645/unifi-switch-tagged-traffic-issues

              Wasn't this thread started because you couldn't get it to work?

              No, that thread - where I am still having problems - is because I can't get my phones to work on their designated VLAN - has nothing to do with Guest access.

              stacksofplatesS 1 Reply Last reply Reply Quote 0
              • stacksofplatesS
                stacksofplates @Dashrender
                last edited by

                @Dashrender said in Concern Around Hackers Using DHCP Pool:

                @stacksofplates said in Concern Around Hackers Using DHCP Pool:

                @Dashrender said in Concern Around Hackers Using DHCP Pool:

                @JaredBusch said in Concern Around Hackers Using DHCP Pool:

                @Dashrender said in Concern Around Hackers Using DHCP Pool:

                I will grant you that the attack is extremely unlikely either against DNS or DHCP, but considering it takes seconds to setup, I don't see the harm in it either. Coupled with the already stated fact of the Windows licensing makes it a requirement in my case since I don't want to setup completely separate APs for guest access.

                Takes seconds? You are having nothing but issues because of wanting a VLAN.

                Thanks - it's true I have a current issue, that's related to VLANs - but this guest network is not one of them. That was installed and working in only seconds longer than it would have taken if I didn't have a VLAN. my current issues are around a legacy network.

                https://mangolassi.it/topic/12645/unifi-switch-tagged-traffic-issues

                Wasn't this thread started because you couldn't get it to work?

                No, that thread - where I am still having problems - is because I can't get my phones to work on their designated VLAN - has nothing to do with Guest access.

                Ah ok. I just have a hard time believing you set up firewall ACLs and switch interfaces in a few seconds.

                1 Reply Last reply Reply Quote 2
                • DashrenderD
                  Dashrender
                  last edited by

                  The title of this thread was also not my intention in this off shoot discussion.

                  The purpose was to show that using corporate resources could lead to problems on the corporate network.
                  In the case of the college, their dedicated IOT network was using DNS from their corporate network. This IOT network was dedicated for college resources - like vending machines and street lights, etc. Over 5000 devices.

                  My intention was more about how an infection on a guest network with access to corporate resources, COULD effect those resources, and as such, simple mitigations could solve this issue.

                  scottalanmillerS 2 Replies Last reply Reply Quote 1
                  • scottalanmillerS
                    scottalanmiller @Dashrender
                    last edited by

                    @Dashrender said in Concern Around Hackers Using DHCP Pool:

                    The title of this thread was also not my intention in this off shoot discussion.

                    The purpose was to show that using corporate resources could lead to problems on the corporate network.
                    In the case of the college, their dedicated IOT network was using DNS from their corporate network. This IOT network was dedicated for college resources - like vending machines and street lights, etc. Over 5000 devices.

                    My intention was more about how an infection on a guest network with access to corporate resources, COULD effect those resources, and as such, simple mitigations could solve this issue.

                    Well you brought it up in the context of a small medical office and that's what we were responding to. This thread started specifically about that and it was @JaredBusch that started it. So that IoT stuff is out of scope. You could have ANOTHER thread about IoT dangers, but that's unrelated to what Jared and I were discussing with you.

                    1 Reply Last reply Reply Quote 0
                    • scottalanmillerS
                      scottalanmiller @Dashrender
                      last edited by

                      @Dashrender said in Concern Around Hackers Using DHCP Pool:

                      In the case of the college, their dedicated IOT network was using DNS from their corporate network.

                      Then it wasn't dedicated 😉

                      DashrenderD 1 Reply Last reply Reply Quote 1
                      • DashrenderD
                        Dashrender @scottalanmiller
                        last edited by

                        @scottalanmiller said in Concern Around Hackers Using DHCP Pool:

                        @Dashrender said in Concern Around Hackers Using DHCP Pool:

                        In the case of the college, their dedicated IOT network was using DNS from their corporate network.

                        Then it wasn't dedicated 😉

                        No, clearly it wasn't dedicated.

                        1 Reply Last reply Reply Quote 0
                        • 1
                        • 2
                        • 3
                        • 1 / 3
                        • First post
                          Last post