Ask Your Question

Revision history [back]

click to hide/show revision 1
initial version

I try to capture the packets on the network to show me if there are DHCP offer's coming from multiple IP's but I just see the one server which is my Domain Controller / DHCP server all in one.

How are you making this capture? The DHCP response with the wrong DNS server might be sent with a unicast packet which means it will not be visible unless you're capture point is in the path of the rogue DHCP server and the client that does the DHCP request. I would suggest using a TAP or SPAN port to one system and boot that system to see where the DHCP packets are coming from.