Roque DHCP Tshoot
Today I had a call that some PCs are getting wrong DNS addresses
from DHCP.
Firstly, I checked the scopes and saw that the DNS servers’
addresses were correct.
After this I was sure that someone installed a roque DHCP
server on the network.
Checking a PC I saw the below:
IP: 10.0.0.140 <--- Correct as the network add is 10.0.0.0/24
GW: 10.0.0.254 <---- Correct
DNS: 192.168.0.1 <---
This is wrong. It should be 10.10.10.100 and 10.10.10.101
The device is cisco router 4331.
I have created an ACL with 2 ACEs. I was actually matching BOOTP
(DHCP) messages.
I also created a packet capture on the router and attached the
ACL.
Exporting the capture, I found the below packet. (You can download it and open it with Wireshark)
Opening the capture, I found the ethernet source address
Tracing the specific mac address (show mac add | in d618) I found
it on a switch port 1/0/21.
To resolve the issue, I had to shut the port. After this I informed
the customer and resolve the ticket.
This is how I troubleshoot a roque DHCP issue today. Hope you
find this information interesting. For any further information regarding
commands etc please contact me on twitter. Contact me also if you faced this
issue and how you found the solution.
Comments
Post a Comment