Re: DISCOVERs from "unknown network segment" - suppress log messages?
"Neufeld, Keith" <[email protected]> Mon, 28 Nov 2022 14:49:16 +0000
| Newsgroups | gmane.network.dhcp.isc.dhcp-client |
|---|---|
| Message-ID | <A0B86891-4ED2-4733-94B1-947F7BA5038A__30730.1135313295$1669646994$gmane$org@wichita.edu> |
Just think given the above, 200 request packets/second relayed to every DHCP server on the network 8-O That’s some serious wastage of resource. As you say, simplest to just firewall the packets and ignore it. Tried that today, unfortunately to no avail. macOS has pf installed, but obviously pf does not / cannot block DHCP packets or the other way round, dhcpd grabs the DISCOVERs before pf rules come into effect. So I’m back to field one… Any other ideas? I'd be inclined to make a dhcpd.conf-not-our-subnets containing subnet declarations with no pools for all the other subnets that show up in your logs and "include" it into your dhcpd.conf . I've had mixed success with "ignore booting" over the years (some versions of the server it works, some it doesn't and I still get logs), but I'd definitely put it into each of the subnet declarations for wishful thinking. I know you already tried it in an individual host declaration, but still worth trying in a subnet. Lacking an "ignore unknown subnets" configuration mechanism, it seems like this might work and be next best. -- Keith Neufeld Director of Networking and Telecommunications Wichita State University -- ISC funds the development of this software with paid support subscriptions. Contact us at https://www.isc.org/contact/ for more information. dhcp-users mailing list [email protected] https://lists.isc.org/mailman/listinfo/dhcp-users