newpersn Posted May 9, 2025 Posted May 9, 2025 Hello Got a strange issue that is effecting one of out VLANS, Since Tuesday we been getting spammed with BAD Address in DCHP. We have tired removing failover between the 2 dc's and nothing has changed. Rebooted both DC's just in case its a software bug, Currently looking at Wireshark but no having much luck with trying to filter to see where its coming from. Any ideas?
PotNoodleTech Posted May 9, 2025 Posted May 9, 2025 Could someone have plugged something in to a port on that VLAN that's trying to act as a DHCP server, a wifi router a 4g router some kind of badly behaved CCTV camera etc?
newpersn Posted May 9, 2025 Author Posted May 9, 2025 We haven't spotted anything plugged in, But this VLAN is byod network which is broadcasted over the wireless network
JRA Posted May 9, 2025 Posted May 9, 2025 Could one of the WAPs have gone rogue and started handing out addresses? Might be worth a look, I'd be suspecting some sort of rogue DHCP server on it somewhere (and would be checking Wireshark as you have.)
newpersn Posted May 9, 2025 Author Posted May 9, 2025 I have just changed the vLAN for our vistors SSID as it was set to the BYOD, (Not sure who set that and how long it been on it) and checked a few switches in case of any rogue. Not had any Bad address within the last 20 mins. (Fingers crossed it was a Rouge AP.) 2
newpersn Posted May 19, 2025 Author Posted May 19, 2025 And bad_address has returned. Back to the drawing board. its also effecting our main vLAN now.
JRA Posted May 19, 2025 Posted May 19, 2025 Pain! Could it be one of your switches doing it even? Is this on all your VLANs now or is it just ones the WAPs can bridge to?
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now