Clients keep sending DHCPDECLINE

Rasmus Bøg Hansen moffe at zz9.dk
Mon Aug 23 07:28:08 UTC 2010


Hi all

Could this be caused by a network loop? I also get multiple ARP replies
in many cases like eg. this:

06:21:43.585145 arp who-has 172.31.0.1 tell 172.16.0.2
06:21:43.585288 arp reply 172.31.0.1 is-at 00:23:df:f9:3d:74
06:21:43.585755 arp reply 172.31.0.1 is-at 00:23:df:f9:3d:74
06:21:43.586362 arp reply 172.31.0.1 is-at 00:23:df:f9:3d:74

I've been dumping traffic (ARP+DHCP on the DHCP server) and as the
problem showed up this morning, I could not see the reason for the
problem:

06:21:27.531866 IP 0.0.0.0.68 > 255.255.255.255.67: BOOTP/DHCP, Request
from 70:f1:a1:03:9f:12, length 300
06:21:27.545151 arp who-has 172.16.221.88 tell 172.16.0.2
06:21:28.000435 IP 172.16.0.2.67 > 172.16.221.88.68: BOOTP/DHCP, Reply,
length 319
06:21:28.006709 IP 0.0.0.0.68 > 255.255.255.255.67: BOOTP/DHCP, Request
from 70:f1:a1:03:9f:12, length 320
06:21:28.545145 arp who-has 172.16.221.88 tell 172.16.0.2
06:21:28.556482 arp reply 172.16.221.88 is-at 70:f1:a1:03:9f:12
06:21:29.486526 arp who-has 172.16.221.88 tell 0.0.0.0
06:21:30.193341 arp who-has 172.16.221.88 (70:f1:a1:03:9f:12) tell
0.0.0.0
06:21:30.325632 IP 0.0.0.0.68 > 255.255.255.255.67: BOOTP/DHCP, Request
from 70:f1:a1:03:9f:12, length 300

There are ARP requests/replies and DHCP requests/replies in between but
no clash between MAC address or IP address.

I have attached the full log from the DISCOVER to the DECLINE.
-------------- next part --------------
An embedded and charset-unspecified text was scrubbed...
Name: dhcp.log
URL: <https://lists.isc.org/pipermail/dhcp-users/attachments/20100823/773484e6/attachment.ksh>
-------------- next part --------------

Best regards
/Rasmus

moffe at zz9.dk hit the keyboard.
Afterwards the following was on the screen:

>  Hi Steinar
>
> I am trying that too. If I do not find the solution before tuesday
> morning, I will put up a sniffer box (I am on location anyway), if I
> can find one.
>
> Best regards
> /Rasmus
>
> Den 22-08-2010 22:17, sthaug at nethelp.no skrev:
>>> Thank you for the suggestion. I am currently dumping arp traffic (of
>>> course, now the problem does not show up!)
>> I recommend running full packet capture of all DHCP traffic on the DHCP
>> server(s) on a regular basis. This has helped me diagnose DHCP problems
>> many times.
>>
>> Steinar Haug, Nethelp consulting, sthaug at nethelp.no
>>

-- 
Rasmus B?g Hansen         || moffe at zz9.dk
C.F. M?llers All? 46, 3tv || http://www.zz9.dk
2300 K?benhavn S          ||


More information about the dhcp-users mailing list