Jump to content

Recommended Posts

Posted

Rogue is probably not the correct term as it's not malicious, more a server left over from an old Network still running and acting as a DHCP server which was it's job in a past life.

Last week a few pc's on a small site of mine were playing up, they could get on the internet but were not seeing any network shares, at first I could not work it out, a few restarts and removing network cables from walls and plugging them back in again got them online, but it still bugged me.

 

This morning it happened again, but this time I noticed that the DHCP address was not what I would have expected it to be, however I did recognise it as coming from an old server that was in the staff room that had been switched off and unplugged months ago when a new network was put in.

 

What I believe has happened since is that some smarty pants has plugged it in and switched it on thinking that they could use it as a pc but soon realised they couldn't, walked away but left it running and over time a few pc's have managed to get their settings from it.

The site has had a number of new staff and someone has been switching it off each night and then switching it on in the morning until last week when they were told to switch it off as it was redundant. I switched it on this morning and the pc's got back all of their shares.

 

So my question is how do I get those few pc's to recognise the correct DHCP address which is given out by a completely separate Core Domain Controller as obviously just switching off the old server does not do it?

 

Many thanks!

Posted

Switch off the old server. On problem clients run the following in the command prompt.

 

ipconfig /release

 

ipconfig /renew

 

What switches are you using? You can configure switches to ignore these dodgy DHCP servers.

Posted
Switch off the old server. On problem clients run the following in the command prompt.

 

ipconfig /release

 

ipconfig /renew

 

What switches are you using? You can configure switches to ignore these dodgy DHCP servers.

 

or log onto this old box and disable the dhcp server service then even if it is on and plugged in dhcp wont start

Posted
or log onto this old box and disable the dhcp server service then even if it is on and plugged in dhcp wont start

 

The server is already shutdown. The clients are stuck with the wrong IP. Doing that won't help get his clients running.

Posted
The server is already shutdown. The clients are stuck with the wrong IP. Doing that won't help get his clients running.

 

true but it should stop it recurring again

Posted

When I see an answer like ipconfig /release etc, my first thought is Doh!, why did I not think of that?

All being well I'll do that tomorrow and if it works the server will come away with me and will either be scrapped, sit in the schools loft or become a test machine for me to learn GPO and other stuff, though thinking about it, it is 10 years old running Edutec Classmaster so probably not up to server 2012....

Thanks for the answers!

Posted
Maybe a side note but we had the same problem started yesterday afternoon still on going real mess of ip addresses and ipads unable to connect and lots of bad address, we are unable to find a rouge dhcp server blaming a mac server at the moment???? or yhgfl???
  • 1 month later...
Posted

had this happen on our network too, Never found the bugger, but when I visited the ipadres of the server from an "affected" client pc, i was greeted by a login page of conceptronic (the brand of the rogue dhcp server)

I finally made it stop by only allowing the right dhcp server in the settings of our manageable switch.

I believe this was the setting:

Trusted DHCP Server IP Lists

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...