<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Alert at unauthorized DHCP server activity.. in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/alert-at-unauthorized-dhcp-server-activity/m-p/37916#M27757</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It happens from time to time that students succeeds to connect a private router to our dorms network and it starts to propose leases that lead nowhere to our clients.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I wonder if my PA500 box can be configured to alert us if it discovers such DHCP lease proposals from other sources than our authorized DHCP servers?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for comments on this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards Tor&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 08 Nov 2013 11:16:59 GMT</pubDate>
    <dc:creator>LCMember4427</dc:creator>
    <dc:date>2013-11-08T11:16:59Z</dc:date>
    <item>
      <title>Alert at unauthorized DHCP server activity..</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/alert-at-unauthorized-dhcp-server-activity/m-p/37916#M27757</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It happens from time to time that students succeeds to connect a private router to our dorms network and it starts to propose leases that lead nowhere to our clients.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I wonder if my PA500 box can be configured to alert us if it discovers such DHCP lease proposals from other sources than our authorized DHCP servers?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for comments on this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards Tor&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Nov 2013 11:16:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/alert-at-unauthorized-dhcp-server-activity/m-p/37916#M27757</guid>
      <dc:creator>LCMember4427</dc:creator>
      <dc:date>2013-11-08T11:16:59Z</dc:date>
    </item>
    <item>
      <title>Re: Alert at unauthorized DHCP server activity..</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/alert-at-unauthorized-dhcp-server-activity/m-p/37917#M27758</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;IMHO - PA cant do that, but much better idea is to use You switch to dosn't let tem do it.&lt;/P&gt;&lt;P&gt;If You have managed switch please find &lt;A href="http://en.wikipedia.org/wiki/DHCP_snooping"&gt;DHCP Snooping&lt;/A&gt; funtion. This will protect your DHCP server and you network from such problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;SLawek&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 08 Nov 2013 13:33:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/alert-at-unauthorized-dhcp-server-activity/m-p/37917#M27758</guid>
      <dc:creator>_slv_</dc:creator>
      <dc:date>2013-11-08T13:33:58Z</dc:date>
    </item>
    <item>
      <title>Re: Alert at unauthorized DHCP server activity..</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/alert-at-unauthorized-dhcp-server-activity/m-p/37918#M27759</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;DHCP Snooping and DCHP Relay is the way to go.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And while you are at it check up for the possibility to use private (or at least protected) vlans aswell.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Configuring the DHCP features of the switch should also end up with configuring DAI, IP Source Guard and Option82 for traceability.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many switch vendors also have extra logging available to log when a rogue dhcp server is detected in the network (that is when you have already configured dchp snooping and dhcp relay which points out which the valid dhcp servers are).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 01 Dec 2013 16:57:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/alert-at-unauthorized-dhcp-server-activity/m-p/37918#M27759</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2013-12-01T16:57:00Z</dc:date>
    </item>
  </channel>
</rss>

