Jump to content

Recommended Posts

Posted

Hi All,

 

We have a spurious issue :-

 

Devices slow to pickup or just fail and get APIPA 169.254.x.x

Only recent change is a power outage

 

Cisco configs, and where written

Switchports set as access with portfast

DHCP on Server 2022, is going up but not giving out anywhere near number of address we would expect

Network wide not just one place

 

Giving static IP works fine, but obviously not practical

I am building another DHCP

 

Has anyone had issues with Server  2022 DHCP?

 

Have also checked basic things like firewall not come on, can ping etc 

 

 

TIA

Alastair

 

 

 

Posted (edited)

We had this issue a few years back, clients would discover, get the offer but fail at request. Weirdly when we moved the switch to another module on the HP core it resolved the issue.

 

It is not the first time I've seen a fault with a switch cause a DHCP issue though and the other case was a single dumb switch, the only switch in the network. I've also seen issues with switches that presented them selves as clients not been able to get to an SMB share.

Edited by Davit2005
Posted

Ours seems more likely to be Cisco related

 

Temporarily removed storm control, set at 10%

DHCP snooping turned on with 4 ports used by 2 hosts allowed

 

show process cpu sorted 

 

DHCP Snooping taking circa 53%

DHCP Snooping HA taking circa 24%

 

Next highest process 0.5%

 

Seems its Cisco related, overall CPU running 86%

 

 

 

Posted
26 minutes ago, Ratcliffepg said:

Had something similar recently after a power outage, caused by a switch issue, powering the switch off and on resolved the issue. After a few hours of fault finding......

 

We did have a planned power outage over the summer, Core shutdown for it.

I was already thinking a bouncing the core later today might be an idea

Posted

I remember reading on Reddit, the June server updates had a DHCP issue and lots of admins skipped the June update for this reason. I don't think t was fixed in July, but the August update fixed whatever the issue was. I installed all the updates and didnt have any issues.

 

 

Posted

Ok so broad answer so far 

 

Storm control 10% - Probably to low, supplier recommended 30% - disabled for moment

After around 30 minutes CPU usage on Core for DHCP Snooping and DHCP Snooping HA dropped, from being circa 53% and 23% 

 

I suspect on a large network with low usage over summer a variable limit of 10% could be the culprit, as soon as we hit that limit, via devices and DHCP broadcast etc DHCP process fails, but machines keep on requesting, the cycle then repeats due to the storm control limit

 

After a while DHCP Snooping and DHCP Snooping HA went higher again circa 30% and 10% respectively, for the moment we have disabled DHCP snooping, overall total CPU usage of 6%

 

 

 

 

Posted (edited)
1 hour ago, Alastairb25 said:

Ok so broad answer so far 

 

Storm control 10% - Probably to low, supplier recommended 30% - disabled for moment

After around 30 minutes CPU usage on Core for DHCP Snooping and DHCP Snooping HA dropped, from being circa 53% and 23% 

 

I suspect on a large network with low usage over summer a variable limit of 10% could be the culprit, as soon as we hit that limit, via devices and DHCP broadcast etc DHCP process fails, but machines keep on requesting, the cycle then repeats due to the storm control limit

 

After a while DHCP Snooping and DHCP Snooping HA went higher again circa 30% and 10% respectively, for the moment we have disabled DHCP snooping, overall total CPU usage of 6%

 

 

 

 

All DHCP snooping does is prevent rogue DHCP servers, you add trusted ports i.e. the DHCP server and uplinks. There should not be any impact to DHCP performance. We rolled it out side wide to all edge switches after a few incidents, i.e. staff member bringing in his own router and thought he was smart by matching our IP range. Took 2 weeks to find the issue, did not go down to well, we were not very happy with him. On a worse day we would of binned it, lol. As it was we disconnected it and left a stern note.

Edited by Davit2005
Posted
22 minutes ago, Davit2005 said:

All DHCP snooping does is prevent rogue DHCP servers, you add trusted ports i.e. the DHCP server and uplinks. There should not be any impact to DHCP performance. We rolled it out side wide to all edge switches after a few incidents, i.e. staff member bringing in his own router and thought he was smart by matching our IP range. Took 2 weeks to find the issue, did not go down to well, we were not very happy with him. On a worse day we would of binned it, lol. As it was we disconnected it and left a stern note.

Are you Cisco or HP?

 

We were concerned at high CPU, its not something we have normally looked to know what is "normal"

 

Will likely put back, we just want to see what works and gradually re implement features and monitor

Posted
On 05/09/2025 at 15:44, Alastairb25 said:

Are you Cisco or HP?

 

We were concerned at high CPU, its not something we have normally looked to know what is "normal"

 

Will likely put back, we just want to see what works and gradually re implement features and monitor

HP all through at the moment. Procurve, some Aruba CX and a few Junipers at the core level. If you have core switches secure physically wise and/or disabled the ports you could potentially leave DHCP snooping off the core as long as no end devices plugged in which could lead to rogue DHCP servers causing issues.

Posted (edited)

HP Procurve mainly i.e. core, edge, distribution and aggregation but a few Aruba CX at edge. Only edge switches have end devices plugged in and all those have DHCP snooping enabled apart from a few that don't support it but those are back office switches (a.k.a top of rack) and all traffic is vlan tagged on those.

 

Sorry for the double post, page did not refresh, lol

Edited by Davit2005

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...