Intermittent access and changing MAC records for the same IP may suggest address conflict. Check the recording times and the design of the network before jumping to a permanent conclusion.

Basic approach

IPv4 address conflict detection helps check if an address is used by another device. However, high availability, proxy ARP, and virtual networks can also produce unexpected mappings. A single browsing screen cannot isolate all descriptions.

Application steps

  1. Record the suspect IP, observed MAC and time information in two separate measurements.
  2. Check that DHCP reservations and manually assigned addresses do not conflict in the same pool.
  3. Compare switch, DHCP and client logs; Plan the change with the knowledge of the device owner.

Practical example

When the camera is manually using .50, .50 can also be given to another client if the DHCP server distributes the .20–.100 range. The solution is a reservation or managed non-pool address plan for the camera; Simply restarting the device is not a permanent solution.

Interpret the result correctly

Do not automatically label MAC changing as an attack. A cluster may be using virtual addresses. Recording the finding separately as confirmed conflict, possible conflict, or unexplained change facilitates subsequent intervention.

Source and follow-up reading

Protocol or command details: RFC 5227. The steps and example scenario are IPScans editorial narrative.