Exhaust a DHCP scope, then catch a rogue DHCP server
Task
Shrink win-srv's DHCP scope to two addresses and bring up a third client to see what scope exhaustion does to it. Then start a second, unauthorised DHCP server on lin-b handing out a wrong gateway, and track down which server gave a client its lease -- the rogue DHCP problem, found from the client's side.
Steps
- Change win-srv's scope so only two addresses are available. Start three clients one after another and save
ip -br -4 addrfrom the third tolab/rogue/exhausted.txt. SaveGet-DhcpServerv4ScopeStatisticstolab/rogue/stats.txt. Restore the scope. - On lin-b, run dnsmasq as a DHCP server for 192.168.56.200 to 192.168.56.210 with router option 192.168.56.99. Renew a client's lease several times, saving
ip routeeach time tolab/rogue/routes.txt. - On a client that received the wrong gateway, find which server issued the lease: the lease file under
/var/lib/dhcpor/var/lib/NetworkManager, ornmcli -f DHCP4 device show. Save the server identifier tolab/rogue/server-id.txt. - Stop dnsmasq on lin-b, renew the client, and save
ip routetolab/rogue/fixed.txt. - Record in
lab/rogue/prevention.txtthe switch feature that would have blocked the rogue server's offers, and which port it trusts.
Verify
These checks run in a POSIX shell: Terminal on macOS or Linux, and on Windows Git Bash (it comes with Git for Windows) or WSL. A stock Windows PowerShell or Command Prompt has no awk or grep, so there the first line fails.
grep -c '192.168.56' lab/rogue/exhausted.txt
grep -Eic 'InUse|PercentageInUse|Free' lab/rogue/stats.txt
grep -c 'default via 192.168.56.99' lab/rogue/routes.txt
grep -Ec '192.168.56.[0-9]+' lab/rogue/server-id.txt
grep -c 'default via 192.168.56.99' lab/rogue/fixed.txt
grep -Eic 'snooping' lab/rogue/prevention.txt
The third client got no lab address when the scope was exhausted -- the first command prints 0. A Linux client, whether NetworkManager, systemd-networkd or dhclient runs it, is simply left with no IPv4 address; a Windows client would have given itself a 169.254 APIPA address, the clue the lesson describes. At least one renewal took the rogue's gateway; the lease names the rogue server's address; and after the rogue stopped, the wrong gateway is gone -- the fifth command prints 0. DHCP snooping trusts only the ports leading to authorised DHCP servers.
Notes
Clients take the first offer that arrives, so a rogue server often wins only some of the time -- which is why rogue DHCP shows up as an intermittent fault affecting some machines and not others.
This is an independent study companion for CompTIA Server+ SK0-005 and is not produced by or endorsed by CompTIA.