Тёмный

UniFi DHCP Guarding - How-to block rogue DHCP servers on your network 

Willie Howe
Подписаться 87 тыс.
Просмотров 7 тыс.
50% 1

Опубликовано:

 

5 окт 2024

Поделиться:

Ссылка:

Скачать:

Готовим ссылку...

Добавить в:

Мой плейлист
Посмотреть позже
Комментарии : 22   
@jakobholzner
@jakobholzner 8 месяцев назад
Would have loved to see some tries from another DHCP server trying to be it’s server
@smmaslanik
@smmaslanik 8 месяцев назад
Would like to hear your explanation of how DNS Shield works too.
@Moonraker11
@Moonraker11 8 месяцев назад
It's basically creating a secure HTTPS tunnel to either Google or Cloudflare to securely send DNS requests. DNS was one of the last core protocols that remained unencrypted...
@JeanPierreWhite
@JeanPierreWhite 8 месяцев назад
Great video. At our church Unifi periodically informs me of a duplicate IP address on our network. I have had no luck tracking down the rogue DHCP server. I'll be turning this on and presumably the rogue device will stop working and we will discover what it is and where it is lol.
@MatSmithLondon
@MatSmithLondon 6 месяцев назад
Or perhaps more likely when you turn this on, it will be more difficult to discover what this is, not less! Either way it's a useful tool to help keep devices on the network in the meantime...
@michaeldrankin
@michaeldrankin 7 месяцев назад
This is great. Would love one on the EDGE series too!
@mtnsolutions
@mtnsolutions 8 месяцев назад
Yeah buddy! Juniper switches come with dhcp guard enabled by default and all access ports are non trusted unless you specifically set them to trust the dhcp server. Can cause headaches if you don’t know but dhcp guard is great to keep in place
@Wahinies
@Wahinies 8 месяцев назад
Yessss this is one of my favorite features because a couple of offices were crippled after somebody brought in Pitney Bowes postage meters that included nano routers by Tplink and these nano routers FORCED DHCP server to on in order to be DHCP CLIENTS like Wtf. Since then i have been adament about using DHCP guarding, snooping, inspection etc. but Unifis solution is bar none the easiest.
@Sjokoz
@Sjokoz 8 месяцев назад
Perfect timing. I am having issues with DHCP Guarding not working. I can see you have DHCP Snooping enabled (which I don't), is that a requirement?
@awprescott
@awprescott 3 месяца назад
Can this be done with Meraki firewall?
@PabloTBrave
@PabloTBrave 5 месяцев назад
Whenever i turn on dhcp guarding i get multiple devices using the same IP
@Moonraker11
@Moonraker11 8 месяцев назад
When you said switch did you mean router (i.e. UDM)?
@WillieHowe
@WillieHowe 8 месяцев назад
This is a switch function -- not a router function.
@peralm6190
@peralm6190 8 месяцев назад
Can't get it to work. I connected an Asus router to the LAN port of my UDR. Then I accessed the WiFi on the Asus router and I connected and got an IP address. I have chosen DHCP Guarding for that network and also specified the UDR gateway address for that network as my DHCP server
@not2tired
@not2tired 4 месяца назад
If I understand properly, anything connected directly to your Asus router will still get DHCP packets from the Asus router. However, the DHCP guarding will prevent DHCP packets from the Asus router from passing through your Unifi switches... so if you plug something into your Unifi switch, and the Asus router tries to give it an IP address, the DHCP guarding will drop that DHCP packets from your Unifi router will be what the new device will receive.
@davesilver5493
@davesilver5493 8 месяцев назад
DHCP Guarding is turned on on my default network but I have two VLANs that multicast two internal originated video feeds to two monitors. Do those VLAN networks need to have guarding on and if so is the IP address of the DHCP server the same as on the defailt network?
@d_must4309
@d_must4309 8 месяцев назад
VLANs are separate networks, with their own DHCP server. DHCP Guarding on your default network is for that range only, it shouldn't be able to communicate with the VLANs
@JeremyLeik
@JeremyLeik 8 месяцев назад
Will this still allow PXE booting?
@JasonsLabVideos
@JasonsLabVideos 8 месяцев назад
Should, PXE doesn't have to do with DHCP hand out.
@JeremyLeik
@JeremyLeik 8 месяцев назад
@@JasonsLabVideos I didn't think it would, but we all know sometimes vendors don't always follow specs well, so I thought it was a question worth asking.
@Wahinies
@Wahinies 8 месяцев назад
It will because PXE boot is a DHCP option in the approved DHCP server identified here by IP.
@jacksoncremean1664
@jacksoncremean1664 8 месяцев назад
does this protect against arp spoofing, what about dynamic arp inspection?
Далее
UniFi WiFi Scheduling
2:39
Просмотров 3,4 тыс.
Source NAT (SNAT) and Destination NAT (DNAT) Explained.
12:43
BEST WiFi Optimization Settings!
20:25
Просмотров 346 тыс.
Lock down DNS on your network
11:55
Просмотров 18 тыс.
NEW to UNIFI VLANs??  START HERE!!!
41:06
Просмотров 73 тыс.
UniFi Layer 3 Switch Access Control Lists
5:29
Просмотров 7 тыс.
Configure VLANs on Unifi Switches
20:13
Просмотров 28 тыс.
To VLAN or not to VLAN - that is the question
6:21
Просмотров 3,7 тыс.
UniFi DNS Server - DNS Records
5:10
Просмотров 8 тыс.