My company received an email from our ISP provider, stating someone had downloaded a copy of the walking dead hardcore. It appears someone had brought in a laptop plugged into our network, connected to a torrent site and started downloading. After explaining what torrent files are and how its used to my manager, we started trying to track the user down. I question my manager about why peer to peer sharing is allowed through our firewall, his eyes glazed over so I left the subject alone.
The laptop has been removed, and hasn't been plugged in since the incident happened. They were issued an IP address, and will be released in 5 days.
If possible, how can I find out what port an IP used, but is no longer plugged into the network? I'm trying to figure out the location, then I would have a pretty good idea who the user is. Then justice will be served with with extreme prejudice.

Thanks