- Community Home
- >
- Servers and Operating Systems
- >
- Legacy
- >
- Networking
- >
- Weird MAC addresses in DHCP Server Logs
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Discussions
Discussions
Discussions
Forums
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО03-29-2001 08:11 AM
тАО03-29-2001 08:11 AM
Weird MAC addresses in DHCP Server Logs
We seem to be getting these from different types of boxes, application servers (DB, etc), Proxies and clients too. The thing is only the clients use DHCP, the servers have static addresses, also none of them are RAS boxes, and our RAS clients use a diffrent range completely.
--snip--
11,03/28/01,16:00:24,Renew,172.16.5.65,AGSHQS0043,5241532070B6D1ED7A50C00102000000
11,03/28/01,16:00:44,Renew,172.16.5.173,AGSHQR0006,52415320F076B0B1D829BF0103000000
--snip--
both these boxes have static IPs. One of them is a proxy the other an application server.
Any ideas anyone???
Thanks in advance.
Nick.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО03-29-2001 08:29 AM
тАО03-29-2001 08:29 AM
Re: Weird MAC addresses in DHCP Server Logs
Do you have any hubs or switches out on your network that might be configured to use BOOTP? Did this just suddenly start happening or have these entries always been there? What kind of clients are on your network (9x, NT, etc)?
What does the weird MAC address look like? Do you have any errors in the System event log? If so, please post the event IDs here. If those are the MAC addresses you are seeing that you posted in your original message, there is definitely something wrong out on the network somewhere because it is too long. The MAC address should be seen as 22 digits. If you convert the first four hex numbers (8 digits) to decimal, it should reflect the subnet address that the DHCP packet originated on. The last twelve digits are the MAC address. You might be able to track down where this is coming from by analyzing the MAC address in that fashion.
If the MAC address you're seeing is longer than 22 digits, I would be looking out on the network for a switch or hub that is sending BOOTP requests, which can confuse the DHCP server. Please reply and let us know what you find out.
Best regards,
Jamie Hughes
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО03-30-2001 12:25 AM
тАО03-30-2001 12:25 AM
Re: Weird MAC addresses in DHCP Server Logs
To re-iterate...
From my DHCP Server Logs:
-> 11,03/29/01,00:17:37,Renew,172.16.5.121,AGS-DTC1552,0000398F7D0D
A renewal with a standard MAC address (0000398F7D0D)
-> 11,03/29/01,00:17:48,Renew,172.16.5.118,AGS-DTC1631,524153204017B3855FA8C00102000000
A renewal with the 'weird' MAC address (524153204017B3855FA8C00102000000) and the first four bytes correspond to 'RAS '
cheers, Nick.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО04-04-2001 12:08 PM
тАО04-04-2001 12:08 PM
Re: Weird MAC addresses in DHCP Server Logs
This website http://www.teleport.com/~jrpetro/FTP_Utilities/tcpnetview.htm
has a piece of software called TCP Netview (freeware) that you may find useful. It should discover the IP and MAC addresses of all network components. Good luck!
Roger
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО05-15-2001 01:16 PM
тАО05-15-2001 01:16 PM