Exhaust a DHCP scope, then catch a rogue DHCP server

applied · 50 min · Objective 4.3

Task

Shrink win-srv's DHCP scope to two addresses and bring up a third client to see what scope exhaustion does to it. Then start a second, unauthorised DHCP server on lin-b handing out a wrong gateway, and track down which server gave a client its lease -- the rogue DHCP problem, found from the client's side.

Steps

  1. Change win-srv's scope so only two addresses are available. Start three clients one after another and save ip -br -4 addr from the third to lab/rogue/exhausted.txt. Save Get-DhcpServerv4ScopeStatistics to lab/rogue/stats.txt. Restore the scope.
  2. On lin-b, run dnsmasq as a DHCP server for 192.168.56.200 to 192.168.56.210 with router option 192.168.56.99. Renew a client's lease several times, saving ip route each time to lab/rogue/routes.txt.
  3. On a client that received the wrong gateway, find which server issued the lease: the lease file under /var/lib/dhcp or /var/lib/NetworkManager, or nmcli -f DHCP4 device show. Save the server identifier to lab/rogue/server-id.txt.
  4. Stop dnsmasq on lin-b, renew the client, and save ip route to lab/rogue/fixed.txt.
  5. Record in lab/rogue/prevention.txt the switch feature that would have blocked the rogue server's offers, and which port it trusts.

Verify

These checks run in a POSIX shell: Terminal on macOS or Linux, and on Windows Git Bash (it comes with Git for Windows) or WSL. A stock Windows PowerShell or Command Prompt has no awk or grep, so there the first line fails.

grep -c '192.168.56' lab/rogue/exhausted.txt
grep -Eic 'InUse|PercentageInUse|Free' lab/rogue/stats.txt
grep -c 'default via 192.168.56.99' lab/rogue/routes.txt
grep -Ec '192.168.56.[0-9]+' lab/rogue/server-id.txt
grep -c 'default via 192.168.56.99' lab/rogue/fixed.txt
grep -Eic 'snooping' lab/rogue/prevention.txt

The third client got no lab address when the scope was exhausted -- the first command prints 0. A Linux client, whether NetworkManager, systemd-networkd or dhclient runs it, is simply left with no IPv4 address; a Windows client would have given itself a 169.254 APIPA address, the clue the lesson describes. At least one renewal took the rogue's gateway; the lease names the rogue server's address; and after the rogue stopped, the wrong gateway is gone -- the fifth command prints 0. DHCP snooping trusts only the ports leading to authorised DHCP servers.

Notes

Clients take the first offer that arrives, so a rogue server often wins only some of the time -- which is why rogue DHCP shows up as an intermittent fault affecting some machines and not others.

This is an independent study companion for CompTIA Server+ SK0-005 and is not produced by or endorsed by CompTIA.