Roque DHCP Tshoot



Today I had a call that some PCs are getting wrong DNS addresses from DHCP.


Firstly, I checked the scopes and saw that the DNS servers’ addresses were correct.


After this I was sure that someone installed a roque DHCP server on the network.

 

Checking a PC I saw the below:

 

IP: 10.0.0.140           <--- Correct as the network add is 10.0.0.0/24

GW: 10.0.0.254        <---- Correct

DNS: 192.168.0.1     <--- This is wrong. It should be 10.10.10.100 and 10.10.10.101

 

The device is cisco router 4331.

I have created an ACL with 2 ACEs. I was actually matching BOOTP (DHCP) messages.


I also created a packet capture on the router and attached the ACL.


Exporting the capture, I found the below packet. (You can download it and open it with Wireshark)

Download Capture

Opening the capture, I found the ethernet source address


 

Tracing the specific mac address (show mac add | in d618) I found it on a switch port 1/0/21.


To resolve the issue, I had to shut the port. After this I informed the customer and resolve the ticket.

 

This is how I troubleshoot a roque DHCP issue today. Hope you find this information interesting. For any further information regarding commands etc please contact me on twitter. Contact me also if you faced this issue and how you found the solution.







Comments

Popular posts from this blog

Upgrade WLC / Supplementary image

Converting lightweigh to standalone AP and vice versa

ISE Direct Upgrade URT