Alastairb25 Posted September 5, 2025 Posted September 5, 2025 Hi All, We have a spurious issue :- Devices slow to pickup or just fail and get APIPA 169.254.x.x Only recent change is a power outage Cisco configs, and where written Switchports set as access with portfast DHCP on Server 2022, is going up but not giving out anywhere near number of address we would expect Network wide not just one place Giving static IP works fine, but obviously not practical I am building another DHCP Has anyone had issues with Server 2022 DHCP? Have also checked basic things like firewall not come on, can ping etc TIA Alastair
Alastairb25 Posted September 5, 2025 Author Posted September 5, 2025 We had a similar issue with 2022 once before A working server randomly stopped A wireshark attached from a non working PC
Alastairb25 Posted September 5, 2025 Author Posted September 5, 2025 Its more like Client has an Offer from DHCP server but fails to send a Request back, then starts on Discover again
Davit2005 Posted September 5, 2025 Posted September 5, 2025 (edited) We had this issue a few years back, clients would discover, get the offer but fail at request. Weirdly when we moved the switch to another module on the HP core it resolved the issue. It is not the first time I've seen a fault with a switch cause a DHCP issue though and the other case was a single dumb switch, the only switch in the network. I've also seen issues with switches that presented them selves as clients not been able to get to an SMB share. Edited September 5, 2025 by Davit2005
Alastairb25 Posted September 5, 2025 Author Posted September 5, 2025 Ours seems more likely to be Cisco related Temporarily removed storm control, set at 10% DHCP snooping turned on with 4 ports used by 2 hosts allowed show process cpu sorted DHCP Snooping taking circa 53% DHCP Snooping HA taking circa 24% Next highest process 0.5% Seems its Cisco related, overall CPU running 86%
Ratcliffepg Posted September 5, 2025 Posted September 5, 2025 Had something similar recently after a power outage, caused by a switch issue, powering the switch off and on resolved the issue. After a few hours of fault finding......
Alastairb25 Posted September 5, 2025 Author Posted September 5, 2025 26 minutes ago, Ratcliffepg said: Had something similar recently after a power outage, caused by a switch issue, powering the switch off and on resolved the issue. After a few hours of fault finding...... We did have a planned power outage over the summer, Core shutdown for it. I was already thinking a bouncing the core later today might be an idea
TwistedHelixis Posted September 5, 2025 Posted September 5, 2025 I remember reading on Reddit, the June server updates had a DHCP issue and lots of admins skipped the June update for this reason. I don't think t was fixed in July, but the August update fixed whatever the issue was. I installed all the updates and didnt have any issues.
Alastairb25 Posted September 5, 2025 Author Posted September 5, 2025 Ok so broad answer so far Storm control 10% - Probably to low, supplier recommended 30% - disabled for moment After around 30 minutes CPU usage on Core for DHCP Snooping and DHCP Snooping HA dropped, from being circa 53% and 23% I suspect on a large network with low usage over summer a variable limit of 10% could be the culprit, as soon as we hit that limit, via devices and DHCP broadcast etc DHCP process fails, but machines keep on requesting, the cycle then repeats due to the storm control limit After a while DHCP Snooping and DHCP Snooping HA went higher again circa 30% and 10% respectively, for the moment we have disabled DHCP snooping, overall total CPU usage of 6%
Davit2005 Posted September 5, 2025 Posted September 5, 2025 (edited) 1 hour ago, Alastairb25 said: Ok so broad answer so far Storm control 10% - Probably to low, supplier recommended 30% - disabled for moment After around 30 minutes CPU usage on Core for DHCP Snooping and DHCP Snooping HA dropped, from being circa 53% and 23% I suspect on a large network with low usage over summer a variable limit of 10% could be the culprit, as soon as we hit that limit, via devices and DHCP broadcast etc DHCP process fails, but machines keep on requesting, the cycle then repeats due to the storm control limit After a while DHCP Snooping and DHCP Snooping HA went higher again circa 30% and 10% respectively, for the moment we have disabled DHCP snooping, overall total CPU usage of 6% All DHCP snooping does is prevent rogue DHCP servers, you add trusted ports i.e. the DHCP server and uplinks. There should not be any impact to DHCP performance. We rolled it out side wide to all edge switches after a few incidents, i.e. staff member bringing in his own router and thought he was smart by matching our IP range. Took 2 weeks to find the issue, did not go down to well, we were not very happy with him. On a worse day we would of binned it, lol. As it was we disconnected it and left a stern note. Edited September 5, 2025 by Davit2005
Alastairb25 Posted September 5, 2025 Author Posted September 5, 2025 22 minutes ago, Davit2005 said: All DHCP snooping does is prevent rogue DHCP servers, you add trusted ports i.e. the DHCP server and uplinks. There should not be any impact to DHCP performance. We rolled it out side wide to all edge switches after a few incidents, i.e. staff member bringing in his own router and thought he was smart by matching our IP range. Took 2 weeks to find the issue, did not go down to well, we were not very happy with him. On a worse day we would of binned it, lol. As it was we disconnected it and left a stern note. Are you Cisco or HP? We were concerned at high CPU, its not something we have normally looked to know what is "normal" Will likely put back, we just want to see what works and gradually re implement features and monitor
Davit2005 Posted September 8, 2025 Posted September 8, 2025 On 05/09/2025 at 15:44, Alastairb25 said: Are you Cisco or HP? We were concerned at high CPU, its not something we have normally looked to know what is "normal" Will likely put back, we just want to see what works and gradually re implement features and monitor HP all through at the moment. Procurve, some Aruba CX and a few Junipers at the core level. If you have core switches secure physically wise and/or disabled the ports you could potentially leave DHCP snooping off the core as long as no end devices plugged in which could lead to rogue DHCP servers causing issues.
Davit2005 Posted September 8, 2025 Posted September 8, 2025 (edited) HP Procurve mainly i.e. core, edge, distribution and aggregation but a few Aruba CX at edge. Only edge switches have end devices plugged in and all those have DHCP snooping enabled apart from a few that don't support it but those are back office switches (a.k.a top of rack) and all traffic is vlan tagged on those. Sorry for the double post, page did not refresh, lol Edited September 8, 2025 by Davit2005
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now