[c-nsp] Tracking down rogue DHCP server

Justin M. Streiner streiner at cluebyfour.org
Mon Aug 15 10:23:17 EDT 2005


On Mon, 15 Aug 2005, Matthew Stainforth wrote:

> if you have the mac address, you can start with one switch and do a 
> "show mac <mac addr>" to find the port the next switch is on.  Repeat 
> until you get to the switch that actually has the device connected to 
> it.  Maybe there's an easier way but that's how I've done it in the 
> past.

If the infrastructure is new enough to support it, DHCP snooping may help 
track and shut down the offending server.

jms


More information about the cisco-nsp mailing list