[c-nsp] Tracking down rogue DHCP server
Justin M. Streiner
streiner at cluebyfour.org
Mon Aug 15 10:23:17 EDT 2005
On Mon, 15 Aug 2005, Matthew Stainforth wrote:
> if you have the mac address, you can start with one switch and do a
> "show mac <mac addr>" to find the port the next switch is on. Repeat
> until you get to the switch that actually has the device connected to
> it. Maybe there's an easier way but that's how I've done it in the
> past.
If the infrastructure is new enough to support it, DHCP snooping may help
track and shut down the offending server.
jms
More information about the cisco-nsp
mailing list