 




<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Network technologies and trends &#187; configure DHCP snooping</title>
	<atom:link href="http://itknowledgeexchange.techtarget.com/network-technologies/tag/configure-dhcp-snooping/feed/" rel="self" type="application/rss+xml" />
	<link>http://itknowledgeexchange.techtarget.com/network-technologies</link>
	<description></description>
	<lastBuildDate>Wed, 15 May 2013 18:52:38 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
		<item>
		<title>How to detect a rouge DHCP server in your network?</title>
		<link>http://itknowledgeexchange.techtarget.com/network-technologies/how-to-detect-a-rouge-dhcp-server-in-your-network/</link>
		<comments>http://itknowledgeexchange.techtarget.com/network-technologies/how-to-detect-a-rouge-dhcp-server-in-your-network/#comments</comments>
		<pubDate>Wed, 09 Dec 2009 09:19:53 +0000</pubDate>
		<dc:creator>Yasir Irfan</dc:creator>
				<category><![CDATA[address resolution protocol]]></category>
		<category><![CDATA[Cisco 3560 Switch]]></category>
		<category><![CDATA[Cisco IOS Switch]]></category>
		<category><![CDATA[Cisco Tips]]></category>
		<category><![CDATA[command prompt]]></category>
		<category><![CDATA[computer]]></category>
		<category><![CDATA[configure DHCP snooping]]></category>
		<category><![CDATA[Detecting Rouge DCHP server]]></category>
		<category><![CDATA[DHCP Server]]></category>
		<category><![CDATA[DHCP Snooping]]></category>
		<category><![CDATA[How to detect a rouge DHCP server in your network]]></category>
		<category><![CDATA[Internet Address]]></category>
		<category><![CDATA[mac address]]></category>
		<category><![CDATA[Network Tips]]></category>
		<category><![CDATA[Network Troubleshooting]]></category>
		<category><![CDATA[PC]]></category>
		<category><![CDATA[Physical Address]]></category>
		<category><![CDATA[rouge]]></category>
		<category><![CDATA[rouge DHCP server]]></category>
		<category><![CDATA[Show mac-address table]]></category>
		<category><![CDATA[shutdown]]></category>
		<category><![CDATA[Virtual PC]]></category>
		<category><![CDATA[Windows 2003 Server]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/network-technologies/how-to-detect-a-rouge-dhcp-server-in-your-network/</guid>
		<description><![CDATA[  Today morning I was late to arrive at my office due to some problems, when I came I saw my colleagues were trying hard to figure out the rouge DHCP server detected in our helpdesk VLAN. All our users in the help desk and call center were getting an IP address from the Rouge [...]]]></description>
				<content:encoded><![CDATA[<p class="MsoNormal" style="margin: 0in 0in 10pt"> </p>
<p class="MsoNormal" style="margin: 0in 0in 10pt"><span style="font-family: Calibri;font-size: small">Today morning I was late to arrive at my office due to some problems, when I came I saw my colleagues were trying hard to figure out the rouge DHCP server detected in our helpdesk VLAN. All our users in the help desk and call center were getting an IP address from the Rouge DHCP server and they were not able to access our Network. I tried to figure out the physical location of the rouge DHCP server but I failed to find.</span></p>
<p class="MsoNormal" style="margin: 0in 0in 10pt"><span style="font-family: Calibri;font-size: small">Immediately I thought let me figure out the Mac address of the rouge DHCP server so that I can block its network access. </span></p>
<p class="MsoNormal" style="margin: 0in 0in 10pt"><span style="font-size: small"><span style="font-family: Calibri">I went one of the affected systems and from the command prompt; I used the “arp –a followed by the rouge DHCP server as show below<strong></strong></span></span></p>
<p class="MsoNormal" style="margin: 0in 0in 10pt"><span style="color: #632423"><span style="font-size: small"><span style="font-family: Calibri">C:\&gt;arp -a 192.168.142.2</span></span></span></p>
<p class="MsoNormal" style="margin: 0in 0in 10pt"><span style="color: #632423"><span style="font-size: small"><span style="font-family: Calibri">Interface: 192.168.142.96 &#8212; 0xb</span></span></span></p>
<p class="MsoNormal" style="margin: 0in 0in 10pt"><span style="color: #632423"><span style="font-size: small"><span style="font-family: Calibri"><span>  </span>Internet Address<span>      </span>Physical Address<span>      </span>Type</span></span></span></p>
<p class="MsoNormal" style="margin: 0in 0in 10pt"><span style="color: #632423"><span style="font-size: small"><span style="font-family: Calibri"><span>  </span>192.168.142.2<span>          </span><span> </span>00-16-35-c1-7f-cc<span>     </span>dynamic</span></span></span></p>
<p class="MsoNormal" style="margin: 0in 0in 10pt"><span style="font-family: Calibri;font-size: small">Once I got the Mac address, immediately I logged into a Cisco 3560 Switch connected in that area. From the privilege mode I used <span style="color: #632423">“show mac-address table”</span> command to figure out the interface in which the rouge DHCP is connected.</span></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt"><span style="color: #244061"><span style="font-size: small"><span style="font-family: Calibri">RRBM-ITD-3560-AS01#sho mac address-table </span></span></span></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt"><span style="color: #244061"><span style="font-size: small"><span style="font-family: Calibri"><span>          </span>Mac Address Table</span></span></span></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt"><span style="color: #244061"><span style="font-size: small"><span style="font-family: Calibri">&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-</span></span></span></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt"><span style="color: #244061"><span style="font-family: Calibri;font-size: small"> </span></span></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt"><span style="color: #244061"><span style="font-size: small"><span style="font-family: Calibri">Vlan<span>    </span>Mac Address<span>       </span>Type<span>        </span>Ports</span></span></span></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt"><span style="color: #244061"><span style="font-size: small"><span style="font-family: Calibri">&#8212;-<span>    </span>&#8212;&#8212;&#8212;&#8211;<span>       </span>&#8212;&#8212;&#8211;<span>    </span>&#8212;&#8211;</span></span></span></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt"><span style="color: #244061"><span style="font-size: small"><span style="font-family: Calibri"><span> </span>All<span>    </span>0100.0ccc.cccc<span>    </span>STATIC<span>      </span>CPU</span></span></span></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt"><span style="color: #244061"><span style="font-size: small"><span style="font-family: Calibri"><span> </span>All<span>    </span>0100.0ccc.cccd<span>    </span>STATIC<span>      </span>CPU</span></span></span></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt"><span style="color: #244061"><span style="font-size: small"><span style="font-family: Calibri">All<span>    </span>ffff.ffff.ffff<span>    </span>STATIC<span>      </span>CPU</span></span></span></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt"><span style="color: #244061"><span style="font-size: small"><span style="font-family: Calibri"><span> </span>129<span>    </span>0000.0c07.ac3a<span>    </span>DYNAMIC<span>     </span>Gi0/52</span></span></span></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt"><span style="color: #244061"><span style="font-size: small"><span style="font-family: Calibri"><span> </span>129<span>    </span>0002.e356.9cfa<span>    </span>DYNAMIC<span>     </span>Gi0/52</span></span></span></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt"><span style="color: #244061"><span style="font-size: small"><span style="font-family: Calibri"><span> </span>129<span>    </span>0002.e356.a78f<span>    </span>DYNAMIC<span>     </span>Gi0/39</span></span></span></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt"><span style="color: #244061"><span style="font-size: small"><span style="font-family: Calibri"><span> </span>129<span>    </span>000e.7fd8.6cff<span>    </span>DYNAMIC<span>     </span>Gi0/7</span></span></span></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt"><span style="color: #244061"><span style="font-size: small"><span style="font-family: Calibri"><span> </span>129<span>    </span>000f.fe0a.1ff7<span>    </span>DYNAMIC<span>     </span>Gi0/22</span></span></span></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt"><strong><span style="font-size: small"><span style="font-family: Calibri"><span style="color: #244061"><span> </span></span><span style="color: #632423">129<span>    </span>0016.35c1.7fcc <span> </span>DYNAMIC<span>     </span>Gi0/36</span></span></span></strong></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt"><span style="color: #244061"><span style="font-size: small"><span style="font-family: Calibri"><span> </span>129<span>    </span>000f.fe6f.5d5c<span>    </span>DYNAMIC<span>     </span>Gi0/52</span></span></span></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt"><span style="color: #244061"><span style="font-size: small"><span style="font-family: Calibri"><span> </span>129<span>    </span>000f.fe6f.5e46<span>    </span>DYNAMIC <span>    </span>Gi0/52</span></span></span></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt"><span style="color: #244061"><span style="font-size: small"><span style="font-family: Calibri"><span> </span>129<span>    </span>000f.fe93.d890<span>    </span>DYNAMIC<span>     </span>Gi0/8</span></span></span></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt"><span style="color: #244061"><span style="font-size: small"><span style="font-family: Calibri"><span> </span>129<span>    </span>000f.fe93.fcb0<span>    </span>DYNAMIC<span>     </span>Gi0/7</span></span></span></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt"><span style="color: #244061"><span style="font-size: small"><span style="font-family: Calibri"><span> </span>129<span>    </span>000f.fe93.fcb8<span>    </span>DYNAMIC<span>     </span>Gi0/52</span></span></span></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt"><span style="color: #244061"><span style="font-size: small"><span style="font-family: Calibri"><span> </span>129<span>    </span>000f.fe96.0920<span>    </span>DYNAMIC<span>     </span>Gi0/38</span></span></span></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt"><span style="color: #244061"><span style="font-size: small"><span style="font-family: Calibri"><span> </span>129<span>    </span>000f.fe96.5478<span>    </span>DYNAMIC<span>     </span>Gi0/52</span></span></span></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt"><span style="color: #244061"><span style="font-size: small"><span style="font-family: Calibri">RRBM-ITD-3560-AS01#</span></span></span></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt"><span style="font-family: Calibri;font-size: small"> </span></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt"><span style="font-family: Calibri;font-size: small">Once I detected the interface to which the rouge DHCP sever connected, I disabled the interface in the Cisco 3560 Switch.</span></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt"><span style="font-family: Calibri;font-size: small"> </span></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt"><span style="color: #244061"><span style="font-size: small"><span style="font-family: Calibri">RRBM-ITD-3560-AS01# configure t</span></span></span></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt"><span style="color: #244061"><span style="font-size: small"><span style="font-family: Calibri">Enter configuration commands, one per line.<span>  </span>End with CNTL/Z.</span></span></span></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt"><span style="color: #244061"><span style="font-size: small"><span style="font-family: Calibri">RRBM-ITD-3560-AS01(config)#interface gigabitEthernet 0/36</span></span></span></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt"><span style="color: #244061"><span style="font-size: small"><span style="font-family: Calibri">RRBM-ITD-3560-AS01(config-if)#shutdown </span></span></span></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt"><span style="color: #244061"><span style="font-size: small"><span style="font-family: Calibri">RRBM-ITD-3560-AS01(config-if)#description ROUGE DHCP</span></span></span></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt"><span style="color: #244061"><span style="font-size: small"><span style="font-family: Calibri">RRBM-ITD-3560-AS01(config-if)#exit</span></span></span></p>
<p class="MsoNormal" style="margin: 0in 0in 10pt"><span style="color: #244061"><span style="font-size: small"><span style="font-family: Calibri">RRBM-ITD-3560-AS01#</span></span></span></p>
<p class="MsoNormal" style="margin: 0in 0in 10pt"><span style="font-family: Calibri;font-size: small">To prevent this from happening I configured the </span><a href="http://itknowledgeexchange.techtarget.com/network-technologies/how-to-configure-dhcp-snooping-in-a-cisco-catalyst-switches/"><span style="font-family: Calibri;font-size: small">DHCP snooping</span></a><span style="font-family: Calibri;font-size: small"> in the Cisco 3560 Switch.</span></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt"><span style="font-family: Calibri;font-size: small">After careful inspection we figured out the rouge DHCP sever was running in a Virtual Machine, one of our aspiring professional was testing Active directory and DHCP services in a Virtual Windows 2003 Server. </span></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt"><span style="font-family: Calibri;font-size: small">Whenever you come across this kind of situation doesn’t panic just try to troubleshoot the problem in a systematic way. Just by following few simple steps you can eliminate this problem.</span></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt"><span style="font-family: Calibri;font-size: small"> </span></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt"><span style="font-family: Calibri;font-size: small">The keys steps</span></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt"><span style="font-family: Calibri;font-size: small">Step 1 – Figure out the MAC address using the <span style="color: #632423">“arp –a” </span>followed by ip address of the rouge DHCP server from the affected PC.</span></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt"><span style="font-family: Calibri;font-size: small">Step 2- Log into your Switch and figure out the interface to which the rouge DHCP server is connected <span style="color: #632423">“Show mac-address table”</span> (Cisco IOS Switches).</span></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt"><span style="font-family: Calibri;font-size: small">Step 3- Disable the interface connected to the rouge DHCP server in your Switch “shutdown” (Cisco IOS Switches).</span></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt"><span style="font-family: Calibri;font-size: small">Step 4 – Take precaution by configuring </span><a href="http://itknowledgeexchange.techtarget.com/network-technologies/how-to-configure-dhcp-snooping-in-a-cisco-catalyst-switches/"><span style="font-family: Calibri;font-size: small">DHCP snooping</span></a><span style="font-family: Calibri;font-size: small"> in your Network.</span></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt"><span style="font-family: Calibri;font-size: small"> </span></p>
<p class="MsoNoSpacing" style="margin: 0in 0in 0pt"><span style="font-size: small"></span></p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/network-technologies/how-to-detect-a-rouge-dhcp-server-in-your-network/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
