Jump to content

Recommended Posts

Posted

I've noticed we have a few odd entries in our DNS for some of our AD joined teacher laptops. 

These only seem to appear for devices on our staff vlan. 

 

I've checked for rogue DHCP, turned off our DHCP (no ip is offered) but random clients seem to get these odd IPs rather than the 10.45.X.X ones they should be getting.

 

Any ideas what else could cause this?

 

Thanks :)dns_ip.png.7a000941fa6868fd55454b9f96580519.png

Posted

Yes they can - We use softether vpn - we have a rule that stops them connecting via the vpn when in school - and the vpn server only offers IP's on the same vlan e.g 10.45.X.X as well. 

Posted

Nothing nope, only our 2 DC's. The only thing we have on 192.168.100.X are our unifi switches and they are set to relay DHCP to our DC's. DHCP guarding is also on. 

 

I've ran some tools to look for rogue DHCP and haven't found anything and Wireshark doesn't show anything other than our 2 DC's -  I've not managed to pry an affected device off a teacher yet. They are laptops that have a wired and wireless nic so not sure if it's something to do with that or not... 

Posted (edited)

Got to the bottom of this today - our clevertouch TV's were sharing their network connection via USB which was being added as an additional nic - we turned off the setting: "Allow the IFP to share network with USB connected device" on the android settings and the issue has gone.

 

Happy Friday!

Edited by russlp
  • Like 2

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...