Michael Posted November 1, 2007 Posted November 1, 2007 Alternatively (I've just thought) in Sophos Enterprise Manager, under one of the tabs it displays the workstation name and its allocated IP. You'd be able to isolate it quickly. I hope you're using Sophos AV Grommit
maniac Posted November 1, 2007 Posted November 1, 2007 I do suspect it is a router/access point That would be my chief suspect, but Grommit said it's one of hundreds of NICs from a given vendor i.e. implies it's a workstation. If it's a router from the same manufacturer as the network cards u have, it may well have the same beginning part of the MAC address. Mike.
K.C.Leblanc Posted November 2, 2007 Posted November 2, 2007 192.168.1.1 is my server IP What is the best cheap/free PC Audit software.. one that will get me the mac numbers... As I have the Mac number but it is a make of Network card that we have hundreds of.. If you just want a quick way to get a list of MAC addresses you need 'Angry IP Scanner'. If you've got managed switches you might be able to search their MAC tables which will list what port they connected through.
laserblazer Posted November 2, 2007 Posted November 2, 2007 Spiceworks will do an audit of all networked equipment including mac addresses. Also does help desk. And it's free. If only it would make the tea! Thanks for the info. I was able to make the tea whilst it got on with the audit.
MyDejaVu Posted November 2, 2007 Posted November 2, 2007 I agree with Michael but I would go a bit further, I would not use the 192.168.*.* on your network because casess like this will happen and you will get confusion to find the source. I would suggest to change your Ip ranges, the only acceptable time would be if you have a small one location network eg. one room only or a test lab where devices plugged to the network are easily controlled.
PiqueABoo Posted November 2, 2007 Posted November 2, 2007 it may well have the same beginning part of the MAC address. "May well" is a bit strong.. recall I'm the one who once wrote and still uses an ARP scanner into which I embed the latest OUI (the IEEE company<->MAC list) every now and again. It might happen, but in practice I rarely see collisions between Vendorcorp's NICs and APs or whatever.
Grommit Posted November 4, 2007 Author Posted November 4, 2007 Easy way to track this down, but you can only do it when no one's using your network, and assuming you have a setup where you can easily isolate sections of your network. 1.Set it pinging on a workstation connected to your central switch. 2. Pull out each fibre in turn, until the ping is un-responsive. Bingo, you know which section of the network it's on. Then you can repeat the same process in that section of the network, find out which switch it is, and then finally narrow it down to a port by doing the same thing on the switch. Might take you a little while to do this, but IMO it's far easier than loading on fancy diagnostics tools to try and find it. Mike. Well seeing as it's the main file server thats the killer.. What freaks me out now is that I disconnect the server from the entire network and it says there is still a conflict ?!?! How can that be when it's connected to nothing .. LOL..
Michael Posted November 4, 2007 Posted November 4, 2007 You "could" have lots of routers or computers on your network all using 192.168.1.1 Very unlikely but indeed possible. I would seriously change your DC IP to something else immediately, such as 192.168.1.10 (for example). Not only will this restore your network, it'll also allow you to investigate the source further. It will also mean that if someone does plug in a device without you knowing, it won't kill your network. Routers/Access Points always come with a static IP in the Class C range, so it makes perfect sense not to setup your DC with 192.168.1.1.
jsnetman Posted November 4, 2007 Posted November 4, 2007 Would agree that the IP address is not the best one to choose for a DC and changing it will be best practice. However you need to look at what can happen or go wrong to the DC if it's the DNS and DHCP/WINS server if you change the IP. http://redmondmag.com/forums/forum_posts.asp?tid=3828&pn=1 http://technet2.microsoft.com/windowsserver/en/library/80e432f2-10b6-4768-8a3e-54e357e8fc441033.mspx?mfr=true
laserblazer Posted November 4, 2007 Posted November 4, 2007 What freaks me out now is that I disconnect the server from the entire network and it says there is still a conflict ?!?! How can that be when it's connected to nothing When I ran Spiceworks it showed the Proxy Server, which was installed by the LEA and I have no control, with a hostname in my laptop range. What had happened was that when I was installing a laptop I had a senior moment and set the IP address as the Gateway address and got a conflict with the Proxy Server. So Spiceworks is acting on information from the DC possibly in DNS. I don't fully understand this and had intended taking a look when I get some time but if anyone can advise me it would be great. I'm wondering if you may have a similar situation, if your server is not connected to the outside world and you are still seeing the IP conflict.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now