Find IP address with Mac -Urgent

Hey guys,
I am dealing with a client that has been down all yesterday as well as today with conflicting IP addresses.  I worked with Microsoft and they were able to find the mac address of another device that was giving out DHCP.  I have tried arp on various servers and could not find that mac even after pinging the broadcast address.  I have tried this command: show ip arp vlan (vlan number) | include (mac address) and all that it can really tell me is what the originating port is.  This lead me to two HP switches which also have the mac address but that list the trunk port as the originating source. I am getting absolutely no where with finding this.  Please help!!!!
Kurt SutulaAsked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Andy BartkiewiczNetwork AnalystCommented:
If your just looking for a mac you should be able to locate it using your managed switches. I don;t know what the command is on HP switches but on Cisco switches i would use mac add add to find out what interface is associated to that mac. You may have to travel through a few switches and repeat the process a few times but you'll find it
Andy BartkiewiczNetwork AnalystCommented:
If it lists a trunk as the originating port, then you need to check the switch that is connected to you over that trunk port for the mac address.
nociSoftware EngineerCommented:
You have to follow the trace through the trunk interface to the uplink switch.. end then check from there ... until you end up with a machine.
It might help to get the first 3 bytes through the following:
The might help identify the device it is coming from.

on switches the command show mac or show cam should be used to find where mac addresses have been seen.
Big Business Goals? Which KPIs Will Help You

The most successful MSPs rely on metrics – known as key performance indicators (KPIs) – for making informed decisions that help their businesses thrive, rather than just survive. This eBook provides an overview of the most important KPIs used by top MSPs.

Qlemo"Batchelor", Developer and EE Topic AdvisorCommented:
What is connected to the trunk? The other of those 2 switches?
What you did is exactly what you can do if you only have a MAC address - try to find out the switch port the MAC address is registered on. The only other clue might come from the manufacturer part of the MAC.
You also need to remind which kind of devices/OS can act as a DHCP server: Linux machines, routers, L3 switches, Windows Server machines.
Having said that, since you can do arp you know the IP address of the DHCP server, and should be able to ping -a that to get a host name which will hopefully tell more.
Kurt SutulaAuthor Commented:
Thanks guys,
I can definitely tell that this is a  Cisco device by the OUID.   I was able to get a ticket in with Cisco.  I'll let you guys know how it goes
Pete LongTechnical ConsultantCommented:
HP-Switch-1# ping is alive, time = 3 ms

Then look for it in the ARP cache;
HP-Switch-1# show arp

 IP ARP table

  IP Address       MAC Address       Type    Port
  ---------------  ----------------- ------- ----    e8b748-c757b0     dynamic 13    005056-a61c1c     dynamic 5  << It’s on port 5    005056-a606d9     dynamic 7

Or if you already know its MAC address;

HP-Switch-1# show mac-address 005056-a61c1c

 Status and Counters - Address Table - 005056-a61c1c

Kurt SutulaAuthor Commented:
Sorry to leave you guys hanging.  Cisco could not find it either, but we were able to work around it by putting in a static arp entry and pointing it to an unused IP address.  That DHCP server is no longer giving out addresses, but the old DHCP leases are out there and still causing conflicts.  I ended up having to create a whole DHCP scope and create a whole to address scheme for that vlan as well as change the IP addresses on all the servers to match.  What a freaking mess!!!

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
nociSoftware EngineerCommented:
you're sure there are no dhcp-helpers aka dhcp-relay on any router? (dhcp-proxies..)
Kurt SutulaAuthor Commented:
No, the only DHCP helper address configuration that I could find on any of their devices was pointing to the Windows Server DHCP, the one that they are supposed to be getting it from.  Even if that is the case and blocking that MAC did break something, it is still better than what they had before.
nociSoftware EngineerCommented:
You probably still need to find the rogue DHCP server as it will continue to obstruct when it either gets adjusted or it might restart breaking stuff when the arp entry gets lost sometime.
Good luck with finding it.
Kurt SutulaAuthor Commented:
Yes that is ideal, it's kind of like finding a needle in a haystack at this point.
Kurt SutulaAuthor Commented:
This solved it.
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today

From novice to tech pro — start learning today.