Link to home
Start Free TrialLog in
Avatar of DP230
DP230Flag for United Kingdom of Great Britain and Northern Ireland

asked on

Mitigate rogue DHCP server in Cisco network

Dear experts, if the Access switch is unconfigurable of DHCP snooping, can we do it on Core switch? (The Dhcp is on Core)

Otherwise, how can we mitigate the rogue DHCP? Thanks!
Avatar of David Favor
David Favor
Flag of United States of America image

First step is to disable admin logins on all your machines... because... anyone with admin privilege can run a DHCP server, accidentally or on purpose.

Once you do this, then just audit all your machines... because if a rogue DHCP server is running somewhere, debugging related problems will be a nightmare + near impossible.
ASKER CERTIFIED SOLUTION
Avatar of Dr. Klahn
Dr. Klahn

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
For finding it: netscan makes it easy, one button to show dhcp servers
https://www.softperfect.com/products/networkscanner/

Mitigation is up to you, depends on what you find I suppose.
Avatar of DP230

ASKER

@Aaron, can you give me the screenshot which show rogue DHCP server is detected?

It looks like any free scanner software
If the access switch can't do DHCP snooping, but can do ACLs on the L2 interfaces, you may be able to accomplish something similar by denying packets with a source port of 67/udp on untrusted interfaces. What model of switch are you using?
Avatar of DP230

ASKER

Hi Jody, core sw is cisco 3850, access sw is cisco SG200
It's the computer picture next to the lightbulb. One click
https://www.softperfect.com/products/networkscanner/manual/
Avatar of DP230

ASKER

Aaron, but is it available in free trial version?
Yes it's available in the free version
Setting a long DHCP lease time can help. If you have it set to say 30 days then devices will almost always renew their lease rather than looking for a new DHCP server.

Other than that, implementing 802.1x will at least prevent users from plugging in a rouge router, or laptop for home.