I can well understand with large networks the ability to configure new PC’s and it on the network and have the convenience of DHCP issue a valid IP and DNS server as a very very useful tool.
However, how many of use consider the security repercussions of handing out access to you total network just by the action of plugging a PC in.
The problem gets worse as the lager you network the more likely you will be dependant on DHCP.
From my point of view if you have a small to moderate Network you should NEVER use DHCP to hand out the keys to you network to anyone who plugs in a PC and the only thing that separates the newly plugged in PC is a password and user name.
It is very very hard to keep track of all the wired access points in your office and so the threat compounds itself.
Security threats come in all different types and we should never forget the internal threat. Any possible situation where one has by just plugging a PC or laptop into ANY RJ socket and does get a valid IP and DNS server is an internal threat you may or may not be able to live with.
If you network not a never ending story in its size managing it without DHCP should be a major consideration.
If you cannot live without automatically assigning IP’s then DONT hand out DNS servers for free. This can be a compromise for large expansive networks.
The other issue to consider is the use of different routes available on you network. I can not image being asked as a security consultant NOT to plan different routes depending on the level of security you need.
NOT every PC needs to have access to each other. All that is needed is your severs ability to see everyone. Defining different routes by not using DHCP on every one or using DHCP and defining different routes using differing subnet masks is an option here.
For a real world issue having Management on the same route as the rest of the office is a definite no no.
Payroll and accounting can also have a different route.
Remember if you have not removed the default hidden share of every XP workstation’s root drive of every physical drive in each PC should not be underestimated or forgotten.
Static assignment of Private IP’s is also helpful for every internal security audit. Sure once DHCP has assigned an IP to a PC it i more than likely subsequent assignment will be the same, however when it comes to internal security audits it wont stand up to any audit investigation.
Using static private addresses may take a little more time during setup, however don’t give out the key to you network to anyone who asks for it unless it is totally not manageable ? due to size and personally I still have security issues ? no matter how big the network.
If you want to comment on this discussion, don’t use the excuse you are too busy. The assignment needs only to be made once and I am not advocating suddenly changing a 300+ workstation Network.
Non emotive discussion is helpful and passionate opinions are respected, however we work in the technology industry where non-fact is not worthy of the time it takes to write it.
Please tell me how you have inviolately secured your network without DHCP and static private network assignment.