Solved

Bad Switch Mac Address

Posted on 2013-11-19
4
371 Views
Last Modified: 2013-12-09
Hello,
I am currently having a problem in my network where there is a device that I’m not aware of that is trying to become the Root Switch, the Mac address of this device is  showing up as an manufacture I’m not using, Is there a good way to track down were the device could be located?

Thanks
0
Comment
Question by:ahmad1467
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
4 Comments
 

Expert Comment

by:Dhurken
ID: 39660040
What model switches are you using?
0
 
LVL 12

Expert Comment

by:Infamus
ID: 39660150
If it is Cisco switch, you can run one of the following command depends on the version of IOS.

sh mac address-table address xxxx.xxxx.xxxx

sh mac-address-table address xxxx.xxxx.xxxx

This will tell you which switch port the MAC address is connected to.
0
 

Expert Comment

by:Dhurken
ID: 39660180
As a follow up to Infamus, if you have a larger infrastructure, you may end up hopping from switch to switch to track down the actual switchport where the device is connected.

If so, you can use sh cdp neighbors detail to see the other Cisco devices connected to your current switch.
0
 
LVL 17

Accepted Solution

by:
TimotiSt earned 500 total points
ID: 39660334
If it does become the root switch, the STP 'root port' will point towards it.
As @Infamus says, you might find it in the mac table with 'sh mac address-table'.
But the main point would be to implement BPDU protection on the edge ports. BPDU-guard can shut down the port, in which case you can find the user without network access pretty quick (if that's accceptable in the organization)...
0

Featured Post

On Demand Webinar - Networking for the Cloud Era

This webinar discusses:
-Common barriers companies experience when moving to the cloud
-How SD-WAN changes the way we look at networks
-Best practices customers should employ moving forward with cloud migration
-What happens behind the scenes of SteelConnect’s one-click button

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Radius Debug Error 16 128
Alcatel Lucent OS6450 switch randomly reboots 4 83
Well known ports and optimal ports scanning range 12 130
Testing and simulating multicast traffic 6 52
This article will step through configuring a SonicWALL appliance to utilize an internal DHCP server for Global VPN Client (GVC) hosts.  There are times when using an external (external to the SonicWALL) DHCP server, such as Windows Servers, isn’t pr…
Arrow Electronics was searching for a KVM  (Keyboard/Video/Mouse) switch that could display on one single monitor the current status of all units being tested on the rack.
Here's a very brief overview of the methods PRTG Network Monitor (https://www.paessler.com/prtg) offers for monitoring bandwidth, to help you decide which methods you´d like to investigate in more detail.  The methods are covered in more detail in o…
This video gives you a great overview about bandwidth monitoring with SNMP and WMI with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're looking for how to monitor bandwidth using netflow or packet s…

737 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question