karldenton Posted November 29, 2016 Posted November 29, 2016 Hi, Does anyone have an idea please what these rogue dhcp clients are in our leases? (Our domain is not bmw.corp) Thanks
localzuk Posted November 29, 2016 Posted November 29, 2016 Well, going from the first 6 characters of each MAC address, they are all HP devices.
Steve21 Posted November 29, 2016 Posted November 29, 2016 (edited) Looks like your DNS is setup wrong and querying externally for local addresses. 192. is part of the BMW ip range for public IP addresses Edit - Either that or you're assinging 192 addresses that aren't private? e.g: nslookup gw01-d.bmwgroup.com Non-authoritative answer: Name: gw01-d.bmwgroup.com Address: 192.109.190.1 Steve Edited November 29, 2016 by Steve21
localzuk Posted November 29, 2016 Posted November 29, 2016 Hmm... As the IPs listed are all 10.10 addresses, the 192 explanation doesn't seem like it could be right. However, I had a thought - do you use anything like VirtualBox or something that has a secondary network card for the device its on? One that is using the 192 range somewhere?
FN-GM Posted November 29, 2016 Posted November 29, 2016 What switches do you have? Could use them to trace back to the port. Could there be a simple explanation like BMW have done a workshop with some kids and plugged into your network in an attempt to get internet? 1
themightymrp Posted November 29, 2016 Posted November 29, 2016 No chance you recently purchased any second hand switches which may have originally belonged to BMW? A long shot I know
Steve21 Posted November 29, 2016 Posted November 29, 2016 Random side question too, you using an emc san/nas? Steve
DMcCoy Posted November 29, 2016 Posted November 29, 2016 Probably laptops or other wireless devices, if a dns suffix is set with group policy then it will retain the fqdn when requesting a dhcp lease. Do you have any open/guest wireless? 1
Davit2005 Posted November 30, 2016 Posted November 30, 2016 This would be my feelings. I've seen external companies bring devices in when I have set the dns suffix via GPO as well.
karldenton Posted November 30, 2016 Author Posted November 30, 2016 Thanks for your help everyone. To answer some questions; Our external sites all have private 192 addresses and connected via the Sophos UTM / RED but these we're showing before we got that. We haven't had anyone from BMW in to do a workshop. If you delete the addresses they re-appear, and you can ping them so its a device that is on somewhere. Our switches are netgear and we don't have any guest wifi
Davit2005 Posted November 30, 2016 Posted November 30, 2016 (edited) As @FN-GM states, you have the MAC addresses so try and trace them back through the switches if you can. On a HP managed switch Simply do i.e. show mac-address 64:31:19:3D:2F:4C . Trace it through the switches, if it is pingable you should find it. Edited November 30, 2016 by Davit2005
FN-GM Posted November 30, 2016 Posted November 30, 2016 Thanks for your help everyone. To answer some questions; Our external sites all have private 192 addresses and connected via the Sophos UTM / RED but these we're showing before we got that. We haven't had anyone from BMW in to do a workshop. If you delete the addresses they re-appear, and you can ping them so its a device that is on somewhere. Our switches are netgear and we don't have any guest wifi Maybe second hand HP printers?
MrEprise Posted November 30, 2016 Posted November 30, 2016 Have you tried using Wireshark to try and pinpoint where the requests are being sent to, or originating from?
pcstru Posted November 30, 2016 Posted November 30, 2016 Could it be someone's BMW in the car park trying to phone home?
pantscat Posted November 30, 2016 Posted November 30, 2016 If you can't trace the mac addresses through your Netgear switches (I would have thought their managed switched would do this, though), how about just setup up mac address filtering in DHCP and see if anyone shouts?
Davit2005 Posted December 2, 2016 Posted December 2, 2016 Create a reservation for the MAC address and give it ip address in wrong ip range on purpose. This will hopefully break the communication and wait till some one complains.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now