- 论坛徽章:
- 0
|
5可用积分
近期公司新配了一批电脑,主板:Intel DG43NB;操作系统:windows xp sp3。这批机器都是静态设置IP。
后来局域网内出现IP冲突现象,查找原因,发现很多陌生IP的MAC都是对应这批电脑的。换句话说,这些电脑的MAC地址对应了两个IP(一个是自己设置的静态IP,一个不知道怎么产生的陌生IP)
如果把某台新电脑的网卡禁用,还是可以ping通那个陌生的IP,如果把网线拔了的话,就ping不通陌生IP了。
请问这是什么原因?
这批电脑MAC地址为:00-1C-C0-93-8A-XX
00-1C-C0-A2-8B-XX
2009-7-10 补充:
根本问题找到了,但是不知道怎么解决。
陌生IP是一台DHCP服务器分配的。
我通过抓包,发现新配的那些电脑,每隔5分钟会发3次DHCP discover请求。但是,我明明设置的是静态IP地址,没有开DHCP,也在“服务”里把“DHCP Client”关掉了。
现在的问题就是:
为什么这些电脑会发DHCP请求?
和安装的XP操作系统有关?还是和intel 82567V-2 Gigabit 网卡有关?
下面是在一台linux电脑上抓包发现的:
- [root@server ~]# tcpdump -e -i eth1 -nn port 67
- tcpdump: verbose output suppressed, use -v or -vv for full protocol decode
- listening on eth1, link-type EN10MB (Ethernet), capture size 96 bytes
- 12:39:50.621677 00:1c:c0:93:89:ff > ff:ff:ff:ff:ff:ff, ethertype IPv4 (0x0800), length 342: 0.0.0.0.68 > 255.255.255.255.67: BOOTP/DHCP, Request from 00:1c:c0:93:89:ff, length: 300
- 12:39:54.191655 00:1c:c0:a2:7f:f5 > ff:ff:ff:ff:ff:ff, ethertype IPv4 (0x0800), length 342: 0.0.0.0.68 > 255.255.255.255.67: BOOTP/DHCP, Request from 00:1c:c0:a2:7f:f5, length: 300
- 12:39:55.072834 00:1c:c0:93:89:ff > ff:ff:ff:ff:ff:ff, ethertype IPv4 (0x0800), length 342: 0.0.0.0.68 > 255.255.255.255.67: BOOTP/DHCP, Request from 00:1c:c0:93:89:ff, length: 300
- 12:39:57.095864 00:1c:c0:a2:50:40 > ff:ff:ff:ff:ff:ff, ethertype IPv4 (0x0800), length 342: 0.0.0.0.68 > 255.255.255.255.67: BOOTP/DHCP, Request from 00:1c:c0:a2:50:40, length: 300
- 12:39:58.743195 00:1c:c0:a2:7f:f5 > ff:ff:ff:ff:ff:ff, ethertype IPv4 (0x0800), length 342: 0.0.0.0.68 > 255.255.255.255.67: BOOTP/DHCP, Request from 00:1c:c0:a2:7f:f5, length: 300
- 12:40:01.749663 00:1c:c0:a2:50:40 > ff:ff:ff:ff:ff:ff, ethertype IPv4 (0x0800), length 342: 0.0.0.0.68 > 255.255.255.255.67: BOOTP/DHCP, Request from 00:1c:c0:a2:50:40, length: 300
- 12:40:03.880531 00:1c:c0:93:89:ff > ff:ff:ff:ff:ff:ff, ethertype IPv4 (0x0800), length 342: 0.0.0.0.68 > 255.255.255.255.67: BOOTP/DHCP, Request from 00:1c:c0:93:89:ff, length: 300
- 12:40:07.753201 00:1c:c0:a2:7f:f5 > ff:ff:ff:ff:ff:ff, ethertype IPv4 (0x0800), length 342: 0.0.0.0.68 > 255.255.255.255.67: BOOTP/DHCP, Request from 00:1c:c0:a2:7f:f5, length: 300
- 12:40:09.949904 00:1c:c0:a2:50:40 > ff:ff:ff:ff:ff:ff, ethertype IPv4 (0x0800), length 342: 0.0.0.0.68 > 255.255.255.255.67: BOOTP/DHCP, Request from 00:1c:c0:a2:50:40, length: 300
复制代码
2009-7-11 补充
进一步探索到了问题现象:
电脑开机后,停在启动菜单上,抓包发现,这台电脑还在发DHCP 查询包。
说明和操作系统无关了
BIOS能设disable的地方,我都设置了,还有能设置stay off的地方
可是仍然还能监听到这台电脑在发DHCP 请求广播包
这是为什么呢???
[ 本帖最后由 yoursmile 于 2009-7-11 11:11 编辑 ] |
|