how do I find an IP address of a computer on our network if I don't the range

Posted on 2013-01-06
Last Modified: 2013-01-06
We changed our ip addresses from to but one of the computers had a static address and I don't know what it was.  How do I find that rogue computer.  I know it's FQDN but that didn't help.  I tried doing a scan of, thru .255, but it doersn't show up.  I'm not physically at the machine or I could use ipconfig /all
Question by:J.R. Sitman
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 8
  • 4
  • 2
  • +4
LVL 24

Expert Comment

ID: 38748593
What did you use to do the scan of

In order to scan that subnet you need the scanning machine to be in the same subnet(i.e. you mention you changed your IP from 16 to 18

Change the IP back and then do the scan and you'll find the pc you are looking for...
LVL 23

Expert Comment

ID: 38748597
I have a basic ping script that will loop through an entire subnet.
This will return a True or False if online

Set objShell = CreateObject("WScript.Shell")

Dim i, ip 

ip = inputbox("Enter Subnet" & vbcrlf & "Exampled 192.168.0")
For i = 1 to 255
Set objExec = objShell.Exec("ping -n 1 -w 1000 " & ip & "." & i)
strPingResults = LCase(objExec.StdOut.ReadAll)
If InStr(strPingResults, "reply from") Then
wscript.echo ip & "." & i & vbtab & "True"
wscript.echo ip & "." & i & vbtab & "False"
End If

Open in new window


Author Comment

by:J.R. Sitman
ID: 38748609
I used WSping Pro.  I already tried scanning the .16 and .18.  

@yo_bee, can you tell me how to run the script?  details, please.
SharePoint Admin?

Enable Your Employees To Focus On The Core With Intuitive Onscreen Guidance That is With You At The Moment of Need.

LVL 24

Expert Comment

ID: 38748617
Sorry can you give more details on what you are trying to do?
What's the output from ipconfig/all on your pc?

I assume you are trying to find an IP address that is already in use somewhere? The scanning software you have will work, but if you are setup in the subnet and try to scan the subnet it won't work obviously...

On your client machine set the subnet mask to of and re-scan and it should work...
LVL 24

Expert Comment

ID: 38748621
Sorry, make the subnet to get the scan to work...
LVL 20

Expert Comment

ID: 38748622
surely its on the same subnet as you used to have?
Have you added an Ip such as to your card so it is on both subnets, so you can ping/search for the old computer.
if you haven't then it will be trying to ping it via your default gateway.
LVL 23

Expert Comment

ID: 38748626
Open notepad and paste the script in there.
Save as > ASCII File with a .vbs extension
Open Command Prompt.
type:   cscript File path and name of the vbs file
example:  cscript c:\PingComputers.vbs
LVL 24

Expert Comment

ID: 38748628
Again my bad(not a good day)

Correct subnet mask is
This will mean you can scan the entire 172.16 - 172.31 subnet - and hence the scan should find what you are looking for...

Author Comment

by:J.R. Sitman
ID: 38748630
The problem is I'm access the server remotely so I can't get to the physical computer or I would run ipconfig /all as I noted in my post.
LVL 24

Accepted Solution

smckeown777 earned 300 total points
ID: 38748638
Yes but you don't need access to the remote computer...i meant ipconfig/all from your server you are on...

Reason your scanner isn't finding the rogue computer(at least my best guess) is that the subnet's are different - what is your existing subnet mask from the server for example?

If its then you are only scanning the 172.18.1.x subnet
If its then you are still only scanning the 172.18.x.x subnet - therefore can never see anything in the 172.16.x.x network...

So if you set the subnet mask to this will allow your scanner to scan every IP in the 172.16.x.x - 172.31.x.x. subnets - and hence find your rogue pc...hope this helps.

Expert Comment

ID: 38748650
"Sorry, make the subnet to get the scan to work... -"

That won't work.  This lost computer will only respond based on its subnet mask.  If it was a /24 network, anything outside of that range of addresses, it will attempt to route to its default gateway.  
To find the computer - your best bet it to set your computer to the old default gateway address and run Wireshark on your computer, then you will capture any computer still using the old address scheme try to communicate beyond the local subnet.  A ping sweep would also good be a good choice.
LVL 57

Expert Comment

by:Mike Kline
ID: 38748652
Have you tried using psexec from Microsoft, you can run commands against remote machines

From the help

This command executes IpConfig on the remote system with the /all switch, and displays the resulting output locally:

psexec \\marklap ipconfig /all

Nice script yo_bee - you should also post that to the TechNet script center


LVL 24

Expert Comment

ID: 38748656
'That won't work.  This lost computer will only respond based on its subnet mask.  If it was a /24 network, anything outside of that range of addresses, it will attempt to route to its default gateway. '

Good point @finfrockg - didn't think of that one...

Back to my original point - you need to change the server back to its original ip and re-run the scan to find this one...

Author Comment

by:J.R. Sitman
ID: 38748675
In my scan software I can't enter the full subnet.  See attached.
LVL 24

Expert Comment

ID: 38748686
Probably since the mask is like I already said...with a mask of it only allows you to change the last 2 octets of the address range...

But as @finfrockg mentions it probably makes no odds - as the remote machine will still have default GW set to the old address(and thus not respond to anything...)

You said you know the machine name - any chance there's still a record for what IP it was using in your DNS records on the server?
LVL 26

Expert Comment

by:Fred Marshall
ID: 38748698
Just to be clear re:
'That won't work.  This lost computer will only respond based on its subnet mask.  If it was a /24 network, anything outside of that range of addresses, it will attempt to route to its default gateway. '

The lost computer will respond to anything it receives if it's set up to respond to ICMP/Pings at all.  
- It *is* the destination and it will receive the packets.
- If suitably configured it should respond.
- If the source (and thus the response destination) IP address is on a subnet different from the target computer's subnet then it will still respond but the next hop will be its gateway on its local subnet.
- I the latter happens, the responding packets will still be "on the wire".
- If the sending computer is on the same wire (i.e. physical LAN) then it may well receive the responding packets.  Well, at least they will be present on the wire even if not in a form that would elicit an action by the pinging computer.

What I don't know is if the packets destined for the sending computer using the local gateway as the next hop will be seen by the sending computer anyway and not rely on the hop.  I *think* so but can't explain why right now .. so I have some doubt.  If the gateway has a broader subnet that includes both subnets then it will often bounce the packets back out onto the LAN.  But some don't.  The necessary experiments are easy to run.

I don't see in any of the responses that the pinging computer is on this, that or another subnet.  There is no ipconfig /all from the pinging computer as asked.  So we remain in the dark re: "is the pinging computer on the appropriate subnet at all?"

Author Closing Comment

by:J.R. Sitman
ID: 38748877
this worked.

Thanks for all the help
LVL 24

Expert Comment

ID: 38748881
Good to know, glad you got sorted...

Featured Post

NFR key for Veeam Backup for Microsoft Office 365

Veeam is happy to provide a free NFR license (for 1 year, up to 10 users). This license allows for the non‑production use of Veeam Backup for Microsoft Office 365 in your home lab without any feature limitations.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Change Exchange 2010 Namespace 6 69
Enabling flash installation using GPO 2 53
Raising Forest Functional Level 2 44
Network Policy to lock out from idle session 7 30
While rebooting windows server 2003 server , it's showing "active directory rebuilding indices please wait" at startup. It took a little while for this process to complete and once we logged on not all the services were started so another reboot is …
Active Directory security has been a hot topic of late, and for good reason. With 90% of the world’s organization using this system to manage access to all parts of their IT infrastructure, knowing how to protect against threats and keep vulnerabil…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles from a Windows Server 2008 domain controller to a Windows Server 2012 domain controlle…
Microsoft Active Directory, the widely used IT infrastructure, is known for its high risk of credential theft. The best way to test your Active Directory’s vulnerabilities to pass-the-ticket, pass-the-hash, privilege escalation, and malware attacks …

732 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question