Finding And Stopping Rogue DHCP Servers On MikroTik

Поделиться
HTML-код
  • Опубликовано: 7 фев 2025

Комментарии • 60

  • @TheNetworkBerg
    @TheNetworkBerg  2 года назад +1

    Pinning this comment with the relevant MikroTik help docs:
    help.mikrotik.com/docs/display/ROS/Bridging+and+Switching#BridgingandSwitching-DHCPSnoopingandDHCPOption82

  • @Joshv918
    @Joshv918 2 года назад +1

    Mikrotik shouted you out!! Pretty cool! Love your videos

  • @anasa.ghannam9302
    @anasa.ghannam9302 2 года назад +1

    thanx man, very useful explanation, and nice Sepultura shirt)))))))

  • @drumer2142
    @drumer2142 2 года назад +2

    Very useful. Thank you so much for teaching us thing like this 💪

  • @amaralarama
    @amaralarama 2 года назад +1

    great video and hell of a t-shirt my man 👍

  • @VladV89
    @VladV89 4 месяца назад +1

    Thanks for video, nice T-shirt!!

    • @TheNetworkBerg
      @TheNetworkBerg  4 месяца назад

      UMA CURA! Hehehe although I love Refuse / Resist and Troops of Doom a lot from Sepultura. Haven't listened to them much recently. Will definitely re-add Sepultura and Soul Fly to my playlists :D!

    • @VladV89
      @VladV89 3 месяца назад

      @@TheNetworkBerg especially "bloody roots" 😎

  • @ahsanmuhammad7428
    @ahsanmuhammad7428 2 года назад +2

    Perfect explanation and demo !

  • @trexx_media
    @trexx_media 2 года назад +4

    ANOTHER INFORMATIVE VIDEO .....

  •  2 года назад +1

    Thank you this with security awernes seams to increase a lot. How about a video to collect and manage logs from the Mikrotik? Line ntopt, greylog and others to detect and prevent intrusion.

  • @kresimirpecar4925
    @kresimirpecar4925 2 года назад +3

    Great video as always, very informative :D I would like to have push notification from the router... Instead of e-mail... I hope mikrotik do something about that... Aruba switches for eg can be managed from the cloud... (I think that notification are enough)

    • @drumer2142
      @drumer2142 2 года назад +1

      In Mikrotiks forum there are a lot of scripts for push notif to email, discord ... etc

  • @petrmiskerik
    @petrmiskerik Год назад

    Awesome, just awesome content. Thx man ♥

  • @Red1Wollip
    @Red1Wollip Год назад

    Another GREAT VIDEO!

  • @miltonesss
    @miltonesss Год назад

    Very useful... thank you so much!

  • @vedatyilmaz4577
    @vedatyilmaz4577 2 года назад +1

    great as usual.

  • @JasonsLabVideos
    @JasonsLabVideos 2 года назад +1

    Awesome video !!

  • @drumaddict89
    @drumaddict89 2 года назад +1

    nice and compact info to cover a lot of topics (especially snooping!)
    thanks for that ... but please give the mic some space ;)

  • @javiermacias5299
    @javiermacias5299 2 года назад

    Thanks for the video, really useful

  • @reanitkhmer3325
    @reanitkhmer3325 2 года назад

    appreciated your video brother.

  • @aaronfish2691
    @aaronfish2691 Год назад

    Love that shirt! Chaos AD!

    • @TheNetworkBerg
      @TheNetworkBerg  Год назад

      🤘Yeah I love Sepultura! Wish I was a bit older when Max came to South Africa in 2004 with SoulFly, sadly my conservative parents wouldn't allow a 15 year old to a metal concert :P

    • @aaronfish2691
      @aaronfish2691 Год назад

      @@TheNetworkBerg I saw Max a number of times with SoulFly. It was definitely something special. I didn't see Sepultura when he was there, unfortunately. I remember when my older brother brought home the first Nailbomb album - thats some good stuff if you haven't heard of it!

  • @salembaabbad8783
    @salembaabbad8783 Год назад +1

    U R Super Pro Expert 😊

  • @oliver1121
    @oliver1121 2 года назад +1

    That was all well and good, but how do you protect it if they keep using smokebomb and vanish?

  • @andrieshrr
    @andrieshrr Год назад

    Great video! What kind of virtualisation software are you using?

    • @TheNetworkBerg
      @TheNetworkBerg  Год назад

      I use VMWare Pro as a hypervisor and the emulation VM I am running is EVE-NG

  •  2 года назад

    Chaos A.D , nice 😁

  • @AhmadAhmad-jf3wb
    @AhmadAhmad-jf3wb 2 года назад

    hello
    great lesson
    can u make lesson about best traffic shapping in mikrotik
    best regards

  • @ruyfranca8756
    @ruyfranca8756 Год назад

    Thank you

  • @jessebustamante6620
    @jessebustamante6620 2 года назад +2

    Love your shirt!!! Love your content! Keep it metal!! Keep it nerd! Don't change!
    #CHAOS_AD

  • @pedro_8240
    @pedro_8240 Год назад +2

    4:39 or, or, or, you do one even better, if your device has a piezo buzzer you could play Seek & Destroy.

  • @truthisunveiled
    @truthisunveiled 2 года назад

    Very good explanation, may I know what tools you are using in the dashboard?

  • @PhamTienPhong
    @PhamTienPhong 9 месяцев назад

    I'm using router on a stick model so I also have VLAN joined a Bridge at Router. Is it necessary to enable DHCP Snooping on Router's Bridge and trust Router's ether2?

  • @IfereUbi-b1w
    @IfereUbi-b1w Год назад

    My scenario is a mk router, with another oem poe switch connected on port 3. The switch hosts my APs. An extender connected to the network to boost signal to grey area is behaving as a rogue server. What do you advise for dhcp snooping since it's only one port that's connected to the mk device ?

  • @shunorrr
    @shunorrr 2 года назад +1

    can you do this with pfsense?

  • @sep_sh
    @sep_sh 11 месяцев назад

    Nice thumbnail

  • @marn200
    @marn200 Год назад

    Wait im new here. 2:15 is a wireshark link integrated into the mikrotik soft/hardware? how did that work?

    • @TheNetworkBerg
      @TheNetworkBerg  Год назад

      Unfortunately not, in this instance Wireshark is integrated with EVE-NG the network emulation software (VM) that I am running to build this topology. What makes this cool is that you run wireshark against any node so I can see the same results on a Cisco, Juniper, Huawei, HPE, etc.

  • @espeyskop792
    @espeyskop792 Год назад

    hi very useful. If you are willing to share also the topic with option 82, it will help a lot. advance thanks.

    • @espeyskop792
      @espeyskop792 Год назад

      additional question. if you are using option 82, you can use at least 2 switches or like you said you need more 1 router for additional requirement?

  • @antoniocerasuolo757
    @antoniocerasuolo757 Год назад

    hi if i have 3 LAN bridges each one with its own DHCP server should i create 3 emntries under ALERTS? or do i need to create one Alert and put all 3 DHCP servers in there??

  • @josepharueyingho9417
    @josepharueyingho9417 Год назад

    Please I would really love to write scripts on my Mikrotik router, How do I go about doing that??

  • @zadekeys2194
    @zadekeys2194 Год назад

    Easiest eay to wirelessly take down a network you are testing - mikrotik as wireless bridge ; once you have internet, then on the wireless bridge enable the dhcp server for the same range and scope as the network youre connecting to... Boom, network will go down and if the core router is rebooted, the Mikrotik will reconnect and the fun will happen again.. as a PoC, you can run the Mikrotik off of a power bank, using a 5v to 12v usb to DC barrel jack cable.

  • @LoveJoyPeaceAndHopeForAll
    @LoveJoyPeaceAndHopeForAll Год назад

    what is the drawing tool used here?

    • @TheNetworkBerg
      @TheNetworkBerg  Год назад

      It is a network emulator called EVE-NG, you can download and install it on a Virtual Machine, it does the same thing as GNS3. You build virtual networks that work like real networks (Because they are real images) to get a better understanding of how to configure or build your networks.

  • @AlanMillerFencepost
    @AlanMillerFencepost 2 года назад

    Would a rogue DHCP server on one of the switches still respond but be blocked? Could the switch then detect and log? Thinking about ways to block them from acting while still being able to detect them because it's an indicator of a problem.

  • @jonpinkley2844
    @jonpinkley2844 2 года назад

    Do you know how this protection is done on the switch-port level? Is it using an "extended" ACL in the switch to block DHCP offers?

  • @over-klen
    @over-klen 2 года назад

    Are you sure that port 2 on switch 1 should be made trusted? What if the rogue server connects instead of the second switch?

    • @TheNetworkBerg
      @TheNetworkBerg  2 года назад

      Then the rogue server will be able to do DHCP again, but this would mean the rogue user would need access to the physical switches and if random people can walk into switching cabinets you have more serious security concerns.
      You would also quickly pick up if half your network drops because a malicious person unplugged a switch.

    • @BattousaiHBr
      @BattousaiHBr Год назад

      @@TheNetworkBerg i just checked the documentation, apparently sw1 ether2 would only have trusted=yes _if_ both sw1 and sw2 are using dhcp option 82, otherwise i'm assuming it would be trusted=no
      this is because when option 82 is enabled for the bridge, it will automatically discard any packet received on untrusted ports if they have an option 82 field.
      no mention on behavior of when option 82 is disabled for the receiving device, but i'm assuming it accepts any dhcp client regardless of option 82 field present or not on untrusted ports and only discards dhcp servers.

  • @Johann75
    @Johann75 2 года назад

    But why not simply isolate all users on Wi-Fi?

  • @1vanch0
    @1vanch0 2 года назад +1

    Refuse/resist rogue dhcp chaos servers ad!

  • @Anavllama
    @Anavllama 2 года назад

    If anyone added a rogue router to a work network, then that person would a. be out of a job and b. behind bars LOL not likely, but very possible at a home network.

    • @BattousaiHBr
      @BattousaiHBr Год назад

      what actually happens is technicians testing replaced commodity routers by connecting it to the local network and not realizing these come with a DHCP server by default, and then wonder why others start complaining that the network stopped working.

  • @ch3vr0n123
    @ch3vr0n123 2 года назад

    is by default dhcp snooping rejection loged? cisco do log by default

    • @raajseeker
      @raajseeker Год назад

      Yes you can do it on SW😊