<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic RE: DHCP Snooping False Positives in ExtremeSwitching (EXOS/Switch Engine)</title>
    <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/dhcp-snooping-false-positives/m-p/25777#M3272</link>
    <description>Create Date: Dec 21 2012 10:26AM&lt;BR /&gt;
&lt;BR /&gt;
Hi Nerfie,&lt;BR /&gt;
Thanks for the Post, infact we have DHCP snooping enabled on our network and I too had this for a long time infact.&lt;BR /&gt;
&lt;BR /&gt;
ipSecur: A Rogue DHCP server with IP 0.0.0.0 was detected on port 9&lt;BR /&gt;
ipSecur: A Rogue DHCP server on VLAN &lt;VLAN&gt; with IP 0.0.0.0 was detected on port 9&lt;BR /&gt;
&lt;BR /&gt;
Regards&lt;BR /&gt;
PJ  (from PRASAD_JACOB)&lt;/VLAN&gt;</description>
    <pubDate>Wed, 08 Jan 2014 05:57:00 GMT</pubDate>
    <dc:creator>EtherNation_Use</dc:creator>
    <dc:date>2014-01-08T05:57:00Z</dc:date>
    <item>
      <title>DHCP Snooping False Positives</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/dhcp-snooping-false-positives/m-p/25775#M3270</link>
      <description>Create Date: Dec 20 2012 11:51AM&lt;BR /&gt;
&lt;BR /&gt;
Hello All!&lt;BR /&gt;
&lt;BR /&gt;
I’ve been using DHCP Snooping on my corporate network and its working as I would expect, apart from a few oddities. Which I would like to point out to you guys and hopefully find people seeing similar. &lt;BR /&gt;
&lt;BR /&gt;
The main focus is an issue we've been experiencing with Windows 7 clients sending DHCP Offer packets instead of acknowledgement/request packets. This causes DHCP snooping to kick into life and to either disable the port or drop the packet, which is what we have it set too after the issues we are seeing. This then causes a log message informing us that an untrusted source has sent a DHCP offer of 0.0.0.0, which we then get alerted on via our syslog server.&lt;BR /&gt;
&lt;BR /&gt;
When this happens it can also take the client PC longer to obtain an IP address. The symptoms/circumstances that can cause this to happen have been tested extensively and we’ve confirmed they are consistent. However, that’s not to say it will always trigger the offer packet from the client. It is seemingly random. Generally speaking, when a laptop is moved from a private network, or another subnet within our corporate network, there’s a chance it will send a DHCP offer packet. Please see example below. Entry one, two, four and five are from the DHCP Servers. The third entry is from the client machine, sending an offer packet itself instead of a request/acknowledgement. &lt;BR /&gt;
&lt;BR /&gt;
58476    12:56:58 16/11/2012        XXX.XXX.XXX.XXX  &lt;LAPTOP name=""&gt;          DHCP:Reply, MsgType = OFFER, TransactionID = 0xE5F0E526&lt;BR /&gt;
&lt;BR /&gt;
 &lt;BR /&gt;
&lt;BR /&gt;
58477    12:56:58 16/11/2012        XXX.XXX.XXX.XXX  &lt;LAPTOP name=""&gt;          DHCP:Reply, MsgType = OFFER, TransactionID = 0xE5F0E526&lt;BR /&gt;
&lt;BR /&gt;
 &lt;BR /&gt;
&lt;BR /&gt;
&lt;B&gt;58494    12:56:58 16/11/2012        0.0.0.0   255.255.255.255                DHCP:Reply, MsgType = OFFER, TransactionID = 0xE5F0E526&lt;/B&gt;&lt;BR /&gt;
&lt;BR /&gt;
 &lt;BR /&gt;
&lt;BR /&gt;
58498    12:56:58 16/11/2012        XXX.XXX.XXX.XXX  255.255.255.255                DHCP:Reply, MsgType = OFFER, TransactionID = 0xE5F0E526&lt;BR /&gt;
&lt;BR /&gt;
 &lt;BR /&gt;
&lt;BR /&gt;
58507    12:56:58 16/11/2012        XXX.XXX.XXX.XXX  255.255.255.255                DHCP:Reply, MsgType = OFFER, TransactionID = 0xE5F0E526&lt;BR /&gt;
&lt;BR /&gt;
Previously we had set the port to block on detection of rogue DHCP Services, however, with the more wide spread rollout of Windows 7 we changed this to just drop the packet. However the frequency and volume of syslog alerts has increased as you would expect.&lt;BR /&gt;
&lt;BR /&gt;
Basically, I’ve submitted my findings to Microsoft and they have confirmed it’s a bug in Windows 7 that was introduced with a hotfix pre-SP1. In order for them to be willing to fix it and to release a hotfix to fix the hotfix, they need to gauge the impact on businesses running Windows 7 with DHCP Snooping enabled on their network. &lt;BR /&gt;
&lt;BR /&gt;
Please can people respond to this thread if they’ve seen some similar behaviour, even if they haven’t been able to explain it please? I’m hoping there are more people out there who have been using DHCP snooping with Windows 7 client s&lt;BR /&gt;
&lt;BR /&gt;
I would like people to respond to this thread please, especially the people using Windows 7 and DHCP snooping and have seen this issue. Even if it hasn’t occurred to you that Windows 7 might have been the issue, any DHCP Snooping false positives would be handy to know about. &lt;BR /&gt;
&lt;BR /&gt;
Googling around, there have been some instances reported with people running a competitors switch setup (not sure if I can mention their name here!  ) and they’re seeing the same issue with DHCP Snooping enabled and Windows 7 being used. So I’m pretty certain it’s in no way an issue with Extreme’s implementation. Take this thread as an example: &lt;BR /&gt;
&lt;BR /&gt;
&lt;A href="http://www.pronetworks.org/forums/windows-7-trying-to-give-dhcp-responses-t118641.html" target="_blank" rel="nofollow noreferrer noopener"&gt;http://www.pronetworks.org/forums/win...&lt;/A&gt;&lt;BR /&gt;
&lt;BR /&gt;
Shows someone also noticing/experiencing the issue, so I’m hoping there are more people here.&lt;BR /&gt;
&lt;BR /&gt;
Many thanks for takign the time to read all of it if you got this far! &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;BR /&gt;
&lt;BR /&gt;
  (from Shaun_Kent)&lt;/LAPTOP&gt;&lt;/LAPTOP&gt;</description>
      <pubDate>Wed, 08 Jan 2014 05:57:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/dhcp-snooping-false-positives/m-p/25775#M3270</guid>
      <dc:creator>EtherNation_Use</dc:creator>
      <dc:date>2014-01-08T05:57:00Z</dc:date>
    </item>
    <item>
      <title>RE: DHCP Snooping False Positives</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/dhcp-snooping-false-positives/m-p/25776#M3271</link>
      <description>Create Date: Dec 20 2012  1:25PM&lt;BR /&gt;
&lt;BR /&gt;
Great post Nerfie thanks for sharing it. I have also sent it on to my customers to inform them of potential issues that they may be seeing.&lt;BR /&gt;
&lt;BR /&gt;
P  (from Paul_Russo)</description>
      <pubDate>Wed, 08 Jan 2014 05:57:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/dhcp-snooping-false-positives/m-p/25776#M3271</guid>
      <dc:creator>EtherNation_Use</dc:creator>
      <dc:date>2014-01-08T05:57:00Z</dc:date>
    </item>
    <item>
      <title>RE: DHCP Snooping False Positives</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/dhcp-snooping-false-positives/m-p/25777#M3272</link>
      <description>Create Date: Dec 21 2012 10:26AM&lt;BR /&gt;
&lt;BR /&gt;
Hi Nerfie,&lt;BR /&gt;
Thanks for the Post, infact we have DHCP snooping enabled on our network and I too had this for a long time infact.&lt;BR /&gt;
&lt;BR /&gt;
ipSecur: A Rogue DHCP server with IP 0.0.0.0 was detected on port 9&lt;BR /&gt;
ipSecur: A Rogue DHCP server on VLAN &lt;VLAN&gt; with IP 0.0.0.0 was detected on port 9&lt;BR /&gt;
&lt;BR /&gt;
Regards&lt;BR /&gt;
PJ  (from PRASAD_JACOB)&lt;/VLAN&gt;</description>
      <pubDate>Wed, 08 Jan 2014 05:57:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/dhcp-snooping-false-positives/m-p/25777#M3272</guid>
      <dc:creator>EtherNation_Use</dc:creator>
      <dc:date>2014-01-08T05:57:00Z</dc:date>
    </item>
    <item>
      <title>RE: DHCP Snooping False Positives</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/dhcp-snooping-false-positives/m-p/25778#M3273</link>
      <description>Create Date: Jan  7 2013  9:14AM&lt;BR /&gt;
&lt;BR /&gt;
@Prusso, Thanks! I hope it helps! Can you confirm how wide spread you've seen this, if at all yet, with your customers? &lt;BR /&gt;
&lt;BR /&gt;
@Pj, Cheers! Glad to see we were not the only ones! Can you confirm if this was due to Windows 7 Clients? &lt;BR /&gt;
&lt;BR /&gt;
  (from Shaun_Kent)</description>
      <pubDate>Wed, 08 Jan 2014 05:57:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/dhcp-snooping-false-positives/m-p/25778#M3273</guid>
      <dc:creator>EtherNation_Use</dc:creator>
      <dc:date>2014-01-08T05:57:00Z</dc:date>
    </item>
    <item>
      <title>RE: DHCP Snooping False Positives</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/dhcp-snooping-false-positives/m-p/25779#M3274</link>
      <description>Create Date: Jan  7 2013 11:16AM&lt;BR /&gt;
&lt;BR /&gt;
HI, in fact all clients were Windows 7&lt;BR /&gt;
&lt;BR /&gt;
Regards&lt;BR /&gt;
PJ  (from PRASAD_JACOB)</description>
      <pubDate>Wed, 08 Jan 2014 05:57:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/dhcp-snooping-false-positives/m-p/25779#M3274</guid>
      <dc:creator>EtherNation_Use</dc:creator>
      <dc:date>2014-01-08T05:57:00Z</dc:date>
    </item>
    <item>
      <title>RE: DHCP Snooping False Positives</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/dhcp-snooping-false-positives/m-p/25780#M3275</link>
      <description>Create Date: Jan  7 2013 11:55AM&lt;BR /&gt;
&lt;BR /&gt;
Thanks PJ, are you investigating every instance of this happening or pretty much ignoring anything which shows up with 0.0.0.0 ? &lt;BR /&gt;
&lt;BR /&gt;
Also, have you noticed any delay in obtaining an IP address with DHCP snooping enabled? Either via Windows clients or say Avaya (or other VoIP based) phones?&lt;BR /&gt;
&lt;BR /&gt;
Cheers!  (from Shaun_Kent)</description>
      <pubDate>Wed, 08 Jan 2014 05:57:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/dhcp-snooping-false-positives/m-p/25780#M3275</guid>
      <dc:creator>EtherNation_Use</dc:creator>
      <dc:date>2014-01-08T05:57:00Z</dc:date>
    </item>
    <item>
      <title>RE: DHCP Snooping False Positives</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/dhcp-snooping-false-positives/m-p/25781#M3276</link>
      <description>Create Date: Jan  9 2013  3:55PM&lt;BR /&gt;
&lt;BR /&gt;
I have definitely seen this on my network, quite a bit actually. I haven't been able to trace it down to windows 7 specifically but that seems to be a common thread (I hadn't found enough machines in time to confirm that was the culprit.)  (from Ansley_Barnes)</description>
      <pubDate>Wed, 08 Jan 2014 05:57:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/dhcp-snooping-false-positives/m-p/25781#M3276</guid>
      <dc:creator>EtherNation_Use</dc:creator>
      <dc:date>2014-01-08T05:57:00Z</dc:date>
    </item>
    <item>
      <title>RE: DHCP Snooping False Positives</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/dhcp-snooping-false-positives/m-p/25782#M3277</link>
      <description>Create Date: Jan 15 2013  3:20PM&lt;BR /&gt;
&lt;BR /&gt;
Hello,&lt;BR /&gt;
&lt;BR /&gt;
I am using DHCP Snooping on my corporate network too.&lt;BR /&gt;
Every few days I get false-positive DHCP-Alerts. From Extreme Switches as well as from HP Switches.&lt;BR /&gt;
It seems like Windows 7 would sporadically reflect a DHCP-Offer, but replaces Source-MAC with its own and Source-IP with 0.0.0.0. The "DHCP Server Identifier" in the packet still contains the IP from the original DHCP-Server.&lt;BR /&gt;
I asked the users what they have done when the DHCP-Alert occured, one docked his notebook into the docking station, another restored an image. But we were not able to reproduce the problem.&lt;BR /&gt;
&lt;BR /&gt;
By the way: Since Windows 7 we also have problems with DHCP Broadcast Storms and IP-Address Conflicts. When someone dismounts his HDD from Computer A and installs it in Computer B, Windows still uses the old IP-Address, it doesn't request a new one. Requirements to reproduce it: Windows 7, DHCP-Reservation (no Pool-IP), enabled APIPA (not disabled in registry). Workaround: I set a registry key to instruct Windows to release the IP-Address on shutdown: HKLM\System\CurrentControlSet\Services\TCPIP\Parameters\Interfaces\&lt;ADAPTER_GUID&gt;\ReleaseOnShutDown = 1 (REG_DWORD)&lt;BR /&gt;
&lt;BR /&gt;
Best regards,&lt;BR /&gt;
Michael  (from MichaelM)&lt;/ADAPTER_GUID&gt;</description>
      <pubDate>Wed, 08 Jan 2014 05:57:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/dhcp-snooping-false-positives/m-p/25782#M3277</guid>
      <dc:creator>EtherNation_Use</dc:creator>
      <dc:date>2014-01-08T05:57:00Z</dc:date>
    </item>
    <item>
      <title>RE: DHCP Snooping False Positives</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/dhcp-snooping-false-positives/m-p/25783#M3278</link>
      <description>Create Date: Jan 23 2013  1:19PM&lt;BR /&gt;
&lt;BR /&gt;
Hi All,&lt;BR /&gt;
&lt;BR /&gt;
we observed the same issues. DHCP snooping is on and under normal circumstances it works perfect. Since we have Dell Notebooks with W7 Pro we got randomly messages that "DHCP violation occured. Blocking MAC ... temporarily. And "A Rogue DHCP server with IP 0.0.0.0 was detected on port .." This only occurs when the notebook starts up. The users didn't mentioned or didn't noticed that the logon process took longer.&lt;BR /&gt;
&lt;BR /&gt;
Regards, Jack Mikel  (from Hans-Michael_Dudek)</description>
      <pubDate>Wed, 08 Jan 2014 05:57:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/dhcp-snooping-false-positives/m-p/25783#M3278</guid>
      <dc:creator>EtherNation_Use</dc:creator>
      <dc:date>2014-01-08T05:57:00Z</dc:date>
    </item>
    <item>
      <title>RE: DHCP Snooping False Positives</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/dhcp-snooping-false-positives/m-p/25784#M3279</link>
      <description>Create Date: Feb 19 2013 12:17PM&lt;BR /&gt;
&lt;BR /&gt;
Thanks for all the feedback everyone.&lt;BR /&gt;
&lt;BR /&gt;
Just an update to let you know that Microsoft should be working on a hotfix as we speak. I will be getting a private release to test, if all goes well, you can all expect the public release via Windows Update in April. &lt;BR /&gt;
&lt;BR /&gt;
Cheers!  (from Shaun_Kent)</description>
      <pubDate>Wed, 08 Jan 2014 05:57:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/dhcp-snooping-false-positives/m-p/25784#M3279</guid>
      <dc:creator>EtherNation_Use</dc:creator>
      <dc:date>2014-01-08T05:57:00Z</dc:date>
    </item>
    <item>
      <title>RE: DHCP Snooping False Positives</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/dhcp-snooping-false-positives/m-p/25785#M3280</link>
      <description>Create Date: Feb 27 2013 10:58AM&lt;BR /&gt;
&lt;BR /&gt;
Hello,&lt;BR /&gt;
&lt;BR /&gt;
Same problem here. We have two Student Residences and discovered DHCP Offer packets from clients with information like:&lt;BR /&gt;
&lt;BR /&gt;
     75462 78.692064000 0.0.0.0 255.255.255.255 DHCP 354 DHCP Offer    - Transaction ID 0x1416f5e5&lt;BR /&gt;
     Ethernet II, Src: AsustekC_XX:XX:XX (48:5b:39:XX:XX:XX), Dst: Broadcast (ff:ff:ff:ff:ff:ff)&lt;BR /&gt;
     Client IP address: 0.0.0.0 (0.0.0.0)&lt;BR /&gt;
     Your (client) IP address: 192.168.1.27 (192.168.1.27) // range not from residence network &lt;BR /&gt;
     Client MAC address: AsustekC_XX:XX:XX (48:5b:39:XX:XX:XX) // client mac address&lt;BR /&gt;
&lt;BR /&gt;
     [Malformed Packet: BOOTP/DHCP]&lt;BR /&gt;
     Expert Info (Error/Malformed): Malformed Packet (Exception occurred)&lt;BR /&gt;
&lt;BR /&gt;
Hope to ear from you soon with Microsoft latest info regarding the hotfix.&lt;BR /&gt;
&lt;BR /&gt;
Best Regards,&lt;BR /&gt;
Eduardo&lt;BR /&gt;
     &lt;BR /&gt;
&lt;BR /&gt;
edit: can you tell us what hotfix is causing this situation? Thanx&lt;BR /&gt;
&lt;BR /&gt;
  (from [eB] )</description>
      <pubDate>Wed, 08 Jan 2014 05:57:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/dhcp-snooping-false-positives/m-p/25785#M3280</guid>
      <dc:creator>EtherNation_Use</dc:creator>
      <dc:date>2014-01-08T05:57:00Z</dc:date>
    </item>
    <item>
      <title>RE: DHCP Snooping False Positives</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/dhcp-snooping-false-positives/m-p/25786#M3281</link>
      <description>Create Date: Mar 11 2013 11:37AM&lt;BR /&gt;
&lt;BR /&gt;
Hi Nerfie&lt;BR /&gt;
&lt;BR /&gt;
We have the same issue in our network. Did you receive a hotfix from microsoft?&lt;BR /&gt;
&lt;BR /&gt;
Regards&lt;BR /&gt;
Markus  (from mafumaso )</description>
      <pubDate>Wed, 08 Jan 2014 05:57:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/dhcp-snooping-false-positives/m-p/25786#M3281</guid>
      <dc:creator>EtherNation_Use</dc:creator>
      <dc:date>2014-01-08T05:57:00Z</dc:date>
    </item>
    <item>
      <title>RE: DHCP Snooping False Positives</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/dhcp-snooping-false-positives/m-p/25787#M3282</link>
      <description>Create Date: May 15 2013 12:05PM&lt;BR /&gt;
&lt;BR /&gt;
Hello all, &lt;BR /&gt;
&lt;BR /&gt;
Apologies for the late response. However I come bearing good news! The hotfix has been released publically and you can find information about it here:&lt;BR /&gt;
&lt;BR /&gt;
&lt;A href="http://support.microsoft.com/kb/2824546" target="_blank" rel="nofollow noreferrer noopener"&gt;http://support.microsoft.com/kb/2824546&lt;/A&gt;&lt;BR /&gt;
&lt;BR /&gt;
Private testing before public release was satisfactory and resolved our issue within the corporate network where it was applied. I hope it also fixes the issues you guys have been seeing similar to me!&lt;BR /&gt;
&lt;BR /&gt;
Cheers!&lt;BR /&gt;
&lt;BR /&gt;
  (from Shaun_Kent)</description>
      <pubDate>Wed, 08 Jan 2014 05:57:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/dhcp-snooping-false-positives/m-p/25787#M3282</guid>
      <dc:creator>EtherNation_Use</dc:creator>
      <dc:date>2014-01-08T05:57:00Z</dc:date>
    </item>
    <item>
      <title>RE: DHCP Snooping False Positives</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/dhcp-snooping-false-positives/m-p/25788#M3283</link>
      <description>Hi All&lt;BR /&gt;
&lt;BR /&gt;
I have been experiencing similar issues on corporate LAN where client machines send DHCP requests very often...about 700-3000 requests in couple of hours....Can you please suggest possible cause and fix.Not all but some of the machines...These machines were updated with drivers but issue persists..&lt;BR /&gt;
&lt;BR /&gt;
Thanks&lt;BR /&gt;
Karan&lt;BR /&gt;</description>
      <pubDate>Wed, 08 Jan 2014 05:57:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/dhcp-snooping-false-positives/m-p/25788#M3283</guid>
      <dc:creator>Karan_Dadwal</dc:creator>
      <dc:date>2014-01-08T05:57:00Z</dc:date>
    </item>
  </channel>
</rss>

