LinuxQuestions.org
Help answer threads with 0 replies.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices



Reply
 
Search this Thread
Old 08-07-2008, 06:23 PM   #1
pgb205
Member
 
Registered: Nov 2007
Posts: 109

Rep: Reputation: 15
Question Scanning network for DHCP servers


we apparently have more than one dhcp server on our network which is causing issues. I tried using nmap -sU 192.168.0.1-254 -p 67
to find all the dhcp servers but doesn't look like this worked. Tried using wireshark and looking for boot.dhcp packet but this again doesn't seem to give consistent results. What utilities are there for linux (or methods available) to find out ip's for all the dhcp servers on a given subnet.

thanks
 
Old 08-07-2008, 06:46 PM   #2
grepmasterd
Member
 
Registered: Aug 2003
Location: Seattle
Distribution: ubuntu, lately
Posts: 182
Blog Entries: 1

Rep: Reputation: 35
if your clients are linux boxes you can examine the dhclient.leases to see what server the lease came from.

~$ locate dhclient*leases
/var/lib/dhcp3/dhclient.leases
/var/lib/dhcp3/dhclient.eth2.leases
/var/lib/dhcp3/dhclient.eth0.leases
/var/lib/dhcp3/dhclient.eth1.leases
/var/lib/dhcp3/dhclient.wlan0.leases


since I know that eth2 is connected to my LAN currently, I can search for the server string in this way

~$ grep dhcp-server-identifier /var/lib/dhcp3/dhclient.eth2.leases
option dhcp-server-identifier 192.168.99.254;
option dhcp-server-identifier 10.5.5.1;


there are my two servers.
 
Old 08-07-2008, 07:52 PM   #3
pgb205
Member
 
Registered: Nov 2007
Posts: 109

Original Poster
Rep: Reputation: 15
If i understood you correctly there is a problem with you method. There is a good chance that you will get information about all DHCP servers in the lan. So linclientA may have information about DHCPServer1 and linclientB may have info from DHCPServer2. But it's also possible that all the linux clients got their information from the same DHCP server. So even I check a few clients there is no guarantee that i have information about ALL the DHCP servers.
 
Old 08-07-2008, 08:02 PM   #4
grepmasterd
Member
 
Registered: Aug 2003
Location: Seattle
Distribution: ubuntu, lately
Posts: 182
Blog Entries: 1

Rep: Reputation: 35
True, it's not an active scan, it's just a good place to look if your intent is to just fix the current problem.

if you want to run scans on a routine basis, there are allegedly tools that will do this. Search google for 'rogue dhcp servers'.

Also, have you seen this?

http://lists.sans.org/pipermail/unis...il/020295.html
 
  


Reply

Tags
dhclient, dhcp, server


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
monitoring/scanning DHCP clients noir911 Linux - Security 1 09-15-2007 09:22 PM
2 dhcp servers 1 network. namit Linux - Software 3 07-14-2007 04:27 PM
DHCP problems - multiple DHCP servers sat86 Linux - Networking 4 10-02-2005 06:43 AM
2 DHCP servers on a network olefemmy Linux - Networking 2 11-19-2004 11:27 AM
2 dhcp servers, 1 network... 330Pilot Linux - Networking 5 10-12-2003 05:10 PM


All times are GMT -5. The time now is 10:28 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
identi.ca: @linuxquestions
Facebook: linuxquestions Google+: linuxquestions
Open Source Consulting | Domain Registration