During a routine audit of a remote branch office, a network technician discovers that several newly installed IP security cameras fail to receive their server-directed configuration profiles upon boot. The cameras are assigned IP addresses in the 192.168.45.0/24 range with a short lease time, but they lack the custom Option 66 parameter pointing to the centralized provisioning server. Further investigation reveals an unauthorized wireless router plugged into a wall port on the same VLAN. Which of the following network host service issues is the MOST likely cause of this problem?
- A rogue DHCP server is responding to broadcast lease requests faster than the legitimate server and offering incomplete scope options.Cevap
- BThe primary DNS server is failing to resolve the fully qualified domain name of the provisioning server for the IP cameras.
- CThe cameras have defaulted to APIPA addressing because no local host service is available on the subnet.
- DThe network firewall is blocking outbound traffic over TCP port 67 to the central provisioning server.
Cevap
A rogue DHCP server on the local subnet is responding to client broadcasts and delivering IP leases without required custom scope options such as Option 66.
When an unauthorized wireless router is connected to a network, its default DHCP service acts as a rogue server. Because DHCP broadcast requests are received by all hosts on the local layer 2 domain, the rogue server can respond faster than the legitimate server. Since consumer routers do not contain corporate scope options like Option 66 (TFTP server specification), devices receiving leases from the rogue server will gain network layer addressing but fail to locate their provisioning server.
Adım Adım Çözüm
Anahtar Kavram
Rogue DHCP Server Identification and Scope Option Delivery