<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Link Layer Based Filtering?</title><link>http://blogs.technet.com/b/teamdhcp/archive/2009/01/21/link-layer-based-filtering.aspx</link><description>Overview 
 The increased threat perception has caused security to be instrumented and enabled at various levels in the enterprise IT infrastructure. Network and system administrators are increasingly becoming security conscious and are constantly on</description><dc:language>en-US</dc:language><generator>Telligent Evolution Platform Developer Build (Build: 5.6.50428.7875)</generator><item><title>re: Link Layer Based Filtering?</title><link>http://blogs.technet.com/b/teamdhcp/archive/2009/01/21/link-layer-based-filtering.aspx#3527819</link><pubDate>Sun, 21 Oct 2012 19:53:25 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3527819</guid><dc:creator>Stephen</dc:creator><description>&lt;p&gt;Nevermind! Found my answer: &lt;a rel="nofollow" target="_new" href="http://technet.microsoft.com/en-us/magazine/ff521761.aspx"&gt;technet.microsoft.com/.../ff521761.aspx&lt;/a&gt;&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3527819" width="1" height="1"&gt;</description></item><item><title>re: Link Layer Based Filtering?</title><link>http://blogs.technet.com/b/teamdhcp/archive/2009/01/21/link-layer-based-filtering.aspx#3527817</link><pubDate>Sun, 21 Oct 2012 19:46:42 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3527817</guid><dc:creator>Stephen</dc:creator><description>&lt;p&gt;You say the deny list takes precedence? I want to deny all mac addresses except for those I explicitly allow. &amp;nbsp;I thought this would be accomplished by adding * to the deny list and adding the individual addresses to the allow list, but if the deny list takes precedence then it would seem that even the allowed devices would be blocked. &amp;nbsp;Obviously I&amp;#39;m not understanding something here. Help?&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3527817" width="1" height="1"&gt;</description></item><item><title>re: Link Layer Based Filtering?</title><link>http://blogs.technet.com/b/teamdhcp/archive/2009/01/21/link-layer-based-filtering.aspx#3280327</link><pubDate>Thu, 10 Sep 2009 13:18:35 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3280327</guid><dc:creator>teamdhcp</dc:creator><description>&lt;p&gt;We have had questions asked of us on the impact of the link layer filtering (aka MAC address based filtering)on the DHCP server performance.&lt;/p&gt;
&lt;p&gt;Based on the testing conducted for measuring impact of MAC address based filtering on performance, we have found negligible performance drop with MAC address based filtering configured.&lt;/p&gt;
&lt;p&gt;With 100,000 MAC addresses configured (50,000 each in allow and deny list), the drop in average response time was to the order of 1-2% across multiple test runs.&lt;/p&gt;
&lt;p&gt;Prasad&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3280327" width="1" height="1"&gt;</description></item><item><title>re: Link Layer Based Filtering?</title><link>http://blogs.technet.com/b/teamdhcp/archive/2009/01/21/link-layer-based-filtering.aspx#3260938</link><pubDate>Fri, 03 Jul 2009 06:27:53 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3260938</guid><dc:creator>teamdhcp</dc:creator><description>&lt;p&gt;Hello Bruce,&lt;/p&gt;
&lt;p&gt; If I understand your concern correctly, you need to have link layer filtering or MAC based filtering in previous version of Windows OS.&lt;/p&gt;
&lt;p&gt; We had been supporting this through our callout dll, please check the following link if it suffices your requirements.&lt;/p&gt;
&lt;p&gt;&lt;a rel="nofollow" target="_new" href="http://blogs.technet.com/teamdhcp/archive/2007/10/03/dhcp-server-callout-dll-for-mac-address-based-filtering.aspx"&gt;http://blogs.technet.com/teamdhcp/archive/2007/10/03/dhcp-server-callout-dll-for-mac-address-based-filtering.aspx&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Thanks,&lt;/p&gt;
&lt;p&gt;Subhash Badri&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3260938" width="1" height="1"&gt;</description></item><item><title>Admin</title><link>http://blogs.technet.com/b/teamdhcp/archive/2009/01/21/link-layer-based-filtering.aspx#3260808</link><pubDate>Thu, 02 Jul 2009 18:34:21 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3260808</guid><dc:creator>Bruce</dc:creator><description>&lt;p&gt;I have not seen the DHCP Security change feature yet and was wondering if there is a download for the DHCP module so that it can be used on all of the Windows 2000, 2003 and 2008 Non-R2 servers. &amp;nbsp;If you have a small business you may not have the budget to upgrade the entire server platform to 2008R2, so what is Microsoft doing to help these types of customers? &amp;nbsp;It would seem Microsoft should provide this to help follow the Presidents lead on Cybersecurity &lt;a rel="nofollow" target="_new" href="http://www.whitehouse.gov/the_press_office/Statement-by-the-President-on-the-White-House-Organization-for-Homeland-Security-and-Counterterrorism/"&gt;http://www.whitehouse.gov/the_press_office/Statement-by-the-President-on-the-White-House-Organization-for-Homeland-Security-and-Counterterrorism/&lt;/a&gt; &lt;/p&gt;
&lt;p&gt;Can anyone tell me if there is a DHCP update for these other platforms that allows an Administrator a way to control which MAC addresses get on your network? &amp;nbsp; I would hope it has a MAC request window to allow the network administrator to see all of the requesting MAC ID’s in a simple window which would have an option to provide a Security ADMIN to allow Once or Allow Permanent Access, Decline Access by the requesting MAC ID selected in the window by an Admin.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3260808" width="1" height="1"&gt;</description></item><item><title>DHCP Server Callout DLL for MAC Address based filtering</title><link>http://blogs.technet.com/b/teamdhcp/archive/2009/01/21/link-layer-based-filtering.aspx#3220904</link><pubDate>Wed, 01 Apr 2009 12:27:02 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3220904</guid><dc:creator>Microsoft Windows DHCP Team Blog</dc:creator><description>&lt;p&gt;DHCP Server team is excited to announce that the much appreciated and loved feature, MAC Address based&lt;/p&gt;
&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3220904" width="1" height="1"&gt;</description></item><item><title>DHCP Server Events Tool</title><link>http://blogs.technet.com/b/teamdhcp/archive/2009/01/21/link-layer-based-filtering.aspx#3215678</link><pubDate>Fri, 20 Mar 2009 15:40:01 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3215678</guid><dc:creator>Microsoft Windows DHCP Team Blog</dc:creator><description>&lt;p&gt;This tool can be used by DHCP Administrators to view all the events generated by Windows DHCP Server&lt;/p&gt;
&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3215678" width="1" height="1"&gt;</description></item><item><title>re: Link Layer Based Filtering?</title><link>http://blogs.technet.com/b/teamdhcp/archive/2009/01/21/link-layer-based-filtering.aspx#3214044</link><pubDate>Tue, 17 Mar 2009 17:13:26 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3214044</guid><dc:creator>teamdhcp</dc:creator><description>&lt;p&gt;Hey Pete,&lt;/p&gt;
&lt;p&gt;In case you were using the MacFilterCallout dll and you have the Maclist.txt file with you, you can use the following tool to import the entries in WS08 R2 DHCP Server:&lt;/p&gt;
&lt;p&gt;&lt;a rel="nofollow" target="_new" href="http://blogs.technet.com/teamdhcp/archive/2009/02/16/mac-filter-import-tool.aspx"&gt;http://blogs.technet.com/teamdhcp/archive/2009/02/16/mac-filter-import-tool.aspx&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Or else,&lt;/p&gt;
&lt;p&gt;the DHCP MMC in WS08 R2 also supports converting active lease to filters.&lt;/p&gt;
&lt;p&gt;Hopefully this would make your job easier.&lt;/p&gt;
&lt;p&gt;Thanks&lt;/p&gt;
&lt;p&gt;Raunak Pandya&lt;/p&gt;
&lt;p&gt;DHCP Server Team&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3214044" width="1" height="1"&gt;</description></item><item><title>re: Link Layer Based Filtering?</title><link>http://blogs.technet.com/b/teamdhcp/archive/2009/01/21/link-layer-based-filtering.aspx#3214040</link><pubDate>Tue, 17 Mar 2009 16:53:24 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3214040</guid><dc:creator>Pete</dc:creator><description>&lt;p&gt;Is there a way of importing a list of MAC addresses into the 2008 R2 DHCP server. I cannot find the MAClist file that there was on the Windows 2003 server version and I have about 800 addresses to be added to the ALLOWED list.&lt;/p&gt;
&lt;p&gt;Thanks&lt;/p&gt;
&lt;p&gt;Pete&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3214040" width="1" height="1"&gt;</description></item><item><title>MAC Filter Import Tool</title><link>http://blogs.technet.com/b/teamdhcp/archive/2009/01/21/link-layer-based-filtering.aspx#3202921</link><pubDate>Mon, 16 Feb 2009 17:02:06 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3202921</guid><dc:creator>Microsoft Windows DHCP Team Blog</dc:creator><description>&lt;p&gt;Hello Everybody, Thanks for all those who tried the MacFilterCallout dll . As you all must have checked&lt;/p&gt;
&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3202921" width="1" height="1"&gt;</description></item></channel></rss>