Is it possible to detect a rogue DHCP server through GenieACS?

Hi everyone,

I’d like to know if there’s any way, using GenieACS or TR-069, to identify whether there’s another device on the customer’s LAN acting as a DHCP server (a rogue DHCP server).

I’m dealing with cases where it appears that another device is handing out IP addresses, causing network conflicts. I’d like to know if it’s possible to detect this remotely from the managed CPE.

I understand that TR-069 doesn’t normally expose LAN DHCP broadcast traffic, but I was wondering if anyone has implemented a solution for this, or if any vendors expose proprietary parameters that could help detect a rogue DHCP server.

Has anyone faced this situation before or found a reliable approach?

Thanks in advance!

Check the AddressSource on the Hosts parameter. If its set to DHCP then the router handed out the IP addr. If Static, then there is a good chance something else is handing out DHCP.

The vendor would need to add proprietary extension for feature that allow to handle rogue DHCP like DHCP snooping but if your device had DHCP snooping configured, you wouldn’t even need to detect the rogue DHCP server since rogue DHCP server would be isolated.

I saw some CPE allowing network capture through CWMP. Capturing port 67 and 68 would be a way to detect an rogue DHCP server. You would be able to find the MAC address through the broadcast.