JRA Posted November 2, 2020 Posted November 2, 2020 Hi all - yes I think from the title we'd all assume rogue DHCP server. And I do also but there is oddness... So, get in and a few folks report they can't log on. Not unusual after half term (cables and mischief) but leads me to check DHCP and I see the scope they're all in has multiple "BAD_ADDRESS" entries in it. It does appear to be limited to this one scope/subnet exclusively. Turn off one of the DHCP servers, delete the BAD_ADDRESS entries, all return in moments. Do the same with the other DHCP server, same thing. So at this point, it's not a problem tied to or from a specific DHCP server. Wiresharking gives me very very little, but maybe something. I run that from one of the DHCP servers with dhcp.option.type == 53 and I keep seeing an IP address that's pinging, but not showing up in DHCP. Wireshark also gives me the MAC address of this device I'm now a little suspicious of. Could be a red herring, could be not. Anyways, go onto my network management VM thing and run the ProCurve Manager suite which lets me find out what port on what switch a device is connected to, and I can search for which MAC address is plugged into any given port on any switch; as in, if the MAC address I type in is plugged into the infrastructure anywhere, this'll sniff it out. Usually, typing in the MAC address will (predictably) bring up a single switch IP, and a single port. However, if I type in THIS MAC address that I have suspicions about, I get a huge list of results that are (quite frankly) bananas. Multiple switch IPs and ports are listed. Core switch and firewall among them. I have no idea what this is telling but I do think this is integral to the problem and at this stage I need a hand. Has anyone got any idea at all how to proceed? Thanks everybody.
JRA Posted November 2, 2020 Author Posted November 2, 2020 Okay, progress narrowing it down a bit. It's not that device. Because that's the gateway out of the subnet. Derp. HOWEVER I *HAVE* discovered it's a wireless device. By turning off the SSID that assigns addresses into that subnet, all goes away and all is well; the BAD_ADDRESS-es don't come back in with that off. The sleuthery continues...
snagrat Posted November 2, 2020 Posted November 2, 2020 I’ve had this before where it is one of those plug in wireless booster things. The MAC address of bad addresses wasn’t the full length, that was a sign. Once I turned off the wireless on said device it stopped. 1
Chaniel Posted November 3, 2020 Posted November 3, 2020 If you're still experiencing this problem, I can't help you narrow it down but something that might alleviate the problem is adding the MAC Address you've identified as dodgy into the DHCP Filter (deny). I've used this in the past to prevent the DHCP server getting full of "BAD_ADDRESS", it doesn't fix the root of the problem but it can help alleviate the symptoms for the rest of the network while you get to the bottom of it. 1
JRA Posted November 13, 2020 Author Posted November 13, 2020 No closer... I think it was either an AP doing *something* or a Samsung Galaxy which did "a suspicious" (single BAD_ADDRESS shows up then that device claims one of the IPs of the BAD_ADDRESSes and then all was ok.) Hmmmmmmmmm...
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now