• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

How to detect rogue DHCP servers on the internal network?

Scheduled Pinned Locked Moved DHCP and DNS
4 Posts 2 Posters 2.4k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • E
    egil
    last edited by Oct 13, 2013, 10:16 AM

    Hi,

    I run the network at a dormitory where we from time to time see people install their wifi routers incorrectly, causing a rogue DHCP server to show up on the network, causing mischief for us.

    Is it possible to set-up a service on pfSense that automatically detects if rogue DHCP servers are present on the network?

    Regards, Egil.

    1 Reply Last reply Reply Quote 0
    • J
      johnpoz LAYER 8 Global Moderator
      last edited by Oct 13, 2013, 1:38 PM Oct 13, 2013, 1:35 PM

      If you have windows here is a older tool that still works

      http://blogs.technet.com/b/teamdhcp/archive/2009/07/03/rogue-dhcp-server-detection.aspx

      But it would be better to prevent than detect wouldn't it - what switches are you using?
      http://en.wikipedia.org/wiki/DHCP_snooping
      http://www.cisco.com/en/US/docs/switches/lan/catalyst6500/ios/12.2SX/configuration/guide/snoodhcp.html

      in linux use dhcp probe

      An intelligent man is sometimes forced to be drunk to spend time with his fools
      If you get confused: Listen to the Music Play
      Please don't Chat/PM me for help, unless mod related
      SG-4860 24.11 | Lab VMs 2.8, 24.11

      1 Reply Last reply Reply Quote 0
      • E
        egil
        last edited by Oct 13, 2013, 3:59 PM

        Hi John,

        Unfortunately, the network topology is the worst kind of homemade, with only a few managed switches here and there, and bad cabling to top it of.
        The switches that can best be described as being the backbone are two ZyXEL GS2200-24P and a Dell PowerConnect 2724.

        I don't know much about DHCP snooping, how to set it up etc., so any advice is welcome indeed. Is it possible on a switch level to block DHCP ACK's that are not coming from a specific MAC address?

        1 Reply Last reply Reply Quote 0
        • J
          johnpoz LAYER 8 Global Moderator
          last edited by Oct 14, 2013, 2:07 AM

          Well your not going to be able to run dhcp snooping unless your switches support it.  And all the switches would need to be able to do it, not just a couple of them.  Or you still would have problems with people connected to the same switch that is down stream from your managed switch..

          I can not believe a school network would run on such crap?

          I would think a school would run decent hardware?  How does tuition not cover a decent network - shit doesn't the school have a computer science program?  This would all be hand on stuff that should be talk in the classes..

          An intelligent man is sometimes forced to be drunk to spend time with his fools
          If you get confused: Listen to the Music Play
          Please don't Chat/PM me for help, unless mod related
          SG-4860 24.11 | Lab VMs 2.8, 24.11

          1 Reply Last reply Reply Quote 0
          4 out of 4
          • First post
            4/4
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
            This community forum collects and processes your personal information.
            consent.not_received