Network+ N10-009 · AP Networking Pilot · Defensive Lab

Rogue DHCP: Detect, Snoop & Inspect

You're the junior network tech at Tidewater Ceramics Co. Staff on the front-desk VLAN report that web logins “look off.” A workstation is receiving a default gateway that doesn't match the documented one — a sign a rogue DHCP server has appeared on the LAN. Detect it on switch TW-CORE-SW1, then lock the segment down with DHCP snooping and Dynamic ARP Inspection (DAI) so only the legitimate server can hand out addresses.

N10-009 4.3 — security features & defense techniques AP NET 2.5 — identify & mitigate vulnerabilities AP NET 3.6 — diagnose & fix a segmented LAN

TW-CORE-SW1 · console

VLAN 40 “STAFF” · 10.40.0.0/24
TW-CORE-SW1>

Client status

live

WS-FRONTDESK-12 · port Gi0/3 · VLAN 40

!
Default gateway in use
10.40.0.137
Does not match documented gateway — DHCP looks hijacked.

Documented gateway: 10.40.0.1 · DNS: 10.40.0.5

Tasks

0 / 6

    Check your understanding

    0 / 3
    Score 0 / 9