pjhtech Tools
UniFi

UniFi Duplicate IP Address or Rogue DHCP Warning

Investigate “Multiple devices are using the same IP address”, static addresses inside DHCP pools and DHCP Guarding without blocking the legitimate server.

For Multiple devices are using the same IP address, remove the overlap between a static host address and the DHCP pool. If clients receive leases from an unintended server instead, stop DHCP on that identified device and configure DHCP Guarding for the real server.

Confirm current ownership

Open Settings → Networks → IP Leases for the affected VLAN and find the disputed IP and MAC. Open the relevant client’s settings and compare Fixed IP Address, if set, with the address configured on the host itself. In the network’s settings read DHCP Range → Start / Stop. A stale client-list entry alone does not establish that two hosts are active.

Example: a printer is statically assigned 192.0.2.50 while the DHCP pool includes .20–.200. A second client can receive .50 unless the allocation excludes or reserves it correctly. Duplicate-address guidance.

Static host overlaps the DHCP pool

For the printer example, change Settings → Networks → affected network → DHCP Range → Start from 192.0.2.20 to 192.0.2.100, keeping Stop at 192.0.2.200, after confirming that this smaller range has capacity. Alternatively, give the printer a verified unused address outside the pool in its own network settings.

On the conflicting Windows DHCP client, run ipconfig to identify its adapter name, then ipconfig /release "Wi-Fi" and ipconfig /renew "Wi-Fi", substituting that name. This briefly disconnects that adapter; use local access. Existing leases do not disappear merely because the pool boundary changed. Update records that point to a changed printer address.

A rogue server supplies the wrong gateway or DNS

For an unintended DHCP server, stop DHCP on the identified device or disable its verified access port in Ports → port → State → Disabled.

On supported UniFi switches, open Settings → Networks → affected network → DHCP Guarding, enable it and enter the trusted DHCP server IP. Use the network gateway IP only when the UniFi gateway is the DHCP server. Verify relayed or third-party DHCP at the guarded segment before applying an allowlist.

A wrong trusted-server value blocks legitimate Offers. Retain the previous guard setting and test a new lease immediately; restore it if the legitimate server is excluded.

Read the offer, not just the assigned address

Use the DHCP capture procedure for one fresh lease attempt and compare Server Identifier, offered address, Router and DNS options. Two Offers may also come from an intentional redundant DHCP design; identify the servers before blocking either. Find the unexpected server IP in Clients, then read its MAC and connected switch/port. If a downstream switch is involved, continue to that switch before disabling a port that also serves legitimate users.

Verify the allocation

Check one intended Offer, a unique address, gateway and DNS, then repeat renewal. After an address correction, verify dependent service records use the new address.

References