Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Rouge dhcp server on WAN

    Scheduled Pinned Locked Moved DHCP and DNS
    8 Posts 2 Posters 623 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • I
      itpp21
      last edited by

      Hello, I have an unwanted (rouge) dhcp server on the WAN side, the ISP is not doing anything about it and I am looking for a way to block this server. (Netgate SG-5100)

      GertjanG 1 Reply Last reply Reply Quote 0
      • GertjanG
        Gertjan @itpp21
        last edited by Gertjan

        @itpp21 : just stop to interact with it ?

        Check the advanced DHCP client option :

        1f5fab39-b2f0-4776-954d-530fc05af5df-image.png

        where you will find :

        aa16eebf-b678-4834-9141-152e58f00cba-image.png

        No "help me" PM's please. Use the forum, the community will thank you.
        Edit : and where are the logs ??

        I 1 Reply Last reply Reply Quote 0
        • I
          itpp21 @Gertjan
          last edited by

          @gertjan Tried that already but it does not stop the requests, eventually it does a 255.255.255.255 and the proper dhcp server replies, 12 hours later the show starts again. I would like to block this server completely from the WAN if possible.

          GertjanG 1 Reply Last reply Reply Quote 0
          • GertjanG
            Gertjan @itpp21
            last edited by

            @itpp21 said in Rouge dhcp server on WAN:

            it does not stop the requests

            The client makes the requests == DHCPDISCOVER and the rogue DHCP might answer with a IP and network : up to you to refuse that network ( IP ).

            No "help me" PM's please. Use the forum, the community will thank you.
            Edit : and where are the logs ??

            I 1 Reply Last reply Reply Quote 0
            • I
              itpp21 @Gertjan
              last edited by

              @gertjan I understand what it does but it would be nice if you could block them completely on the WAN side, can you or anyone else confirm if this is possible or not?

              GertjanG 1 Reply Last reply Reply Quote 0
              • GertjanG
                Gertjan @itpp21
                last edited by

                By RFC the DHCP client is broadcasting. So any server type that can receive the answer can also reply.
                The real solution would be : kill this rogue device.
                Or have it killed, as only your ISP is (should !) capable of controlling your WAN network.

                No "help me" PM's please. Use the forum, the community will thank you.
                Edit : and where are the logs ??

                I 1 Reply Last reply Reply Quote 0
                • I
                  itpp21 @Gertjan
                  last edited by

                  I agree the ISP should take action (unless this is part of a lawfull interception package) but I can't see them do anything, they haven't even acknowledged they are causing a potential problem.

                  I 1 Reply Last reply Reply Quote 0
                  • I
                    itpp21 @itpp21
                    last edited by

                    See solution:
                    https://forum.netgate.com/topic/141362/dhcp-client-unable-to-get-lease-from-cable-provider-solved/4?_=1614433865506

                    1 Reply Last reply Reply Quote 0
                    • First post
                      Last post
                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.