LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 11-11-2014, 01:35 PM   #1
ron7000
Member
 
Registered: Nov 2007
Location: CT
Posts: 248

Rep: Reputation: 26
static ip versus dchp dns regarding security


option a: have a system on a network configured with a static ip address.

option b: that system on the network is configured as dynamic ip to be retrieved via dhcp.

is the following true:
(a) is better because since i know what the ip address is because it is static and because I set it, then i should always be able to get to that ip address knowing that it is my system and not some other system. Where as option b the system can have any arbitrary ip address that is not controlled by me but by a dhcp server and the system name is registered with DNS on the network - all done by someone else, therefore that is a potential security risk from my point of view? for example, with option b if my system name is pigeon and i do "ssh pigeon", then i am relying on dns being correct in sending me to my system and not some other system which is a potential risk? i'm looking at this from a security point of view, and not a network management/logistic point of view.

and with ssh i know you have keys and that would be an immediate red flag, but disregard ssh keys or assume some other remote log on method.
 
Old 11-11-2014, 02:05 PM   #2
suicidaleggroll
LQ Guru
 
Registered: Nov 2010
Location: Colorado
Distribution: OpenSUSE, CentOS
Posts: 5,573

Rep: Reputation: 2142Reputation: 2142Reputation: 2142Reputation: 2142Reputation: 2142Reputation: 2142Reputation: 2142Reputation: 2142Reputation: 2142Reputation: 2142Reputation: 2142
If you don't trust the network, then neither are secure. Somebody could easily unplug the network cable from your box (or pull the power plug) and plug in another box with the same static IP.

The main difference is that option a is more reliable. If the DHCP server goes down, nothing changes on option a, while the entire network shuts down on option b. On the flip side, option b is easier to maintain, since switching subnets, for example, simply requires changing the DHCP address range on the DHCP server, instead of manually changing the static IP on every single box on the network.
 
Old 11-11-2014, 02:34 PM   #3
jefro
Moderator
 
Registered: Mar 2008
Posts: 21,982

Rep: Reputation: 3626Reputation: 3626Reputation: 3626Reputation: 3626Reputation: 3626Reputation: 3626Reputation: 3626Reputation: 3626Reputation: 3626Reputation: 3626Reputation: 3626
Any connection is a security issue. It is possible that some fault lies in software that can be taken advantage of in dhcp I guess so from a very remote stance, a static may be slightly more secure. However from an IP tcp/ip point of view that is not the reason your data is being hacked or threatened.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
[SOLVED] KDE versus Xfce on security of root textillis Linux - Newbie 17 05-17-2013 02:01 AM
Static DCHP problems simpzoid Linux - Networking 10 06-16-2012 10:20 AM
Linux security versus Windows security garylmartin Linux - General 2 09-11-2009 09:41 AM
Re: SElinux and OpenBSD security versus other OS? wardialer Linux - Security 2 09-10-2004 11:58 PM
Ip, Dns & Dchp ??? gigglesnorter Linux - Networking 1 04-20-2004 03:56 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 10:19 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration