× NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.
Orbi WiFi 7 RBE973
Reply

DHCP Snooping Block DNS Packet

Arnaud_D
Aspirant

DHCP Snooping Block DNS Packet

Hi,

 

I've just encounter an issue with my GS724TPv2. As soon as I enabled the DHCP Snooping mode, I cant make dns resolving.

Trusted Inferfaces are ok, and I retrieve an Ip from my dhcp server (which is the same as my dns server). I can ping, go to web servers (with their ips).

 

If I turn off DHCP snooping mode, it works again (mac address validation didnts seem to have an impact), I can see my computer informations in the dynamic binding configuration screen.

 

I have 3   724tp connected with LACP, i tried with one switch alone, no results

 

I have DHCP snooping/filtering set up on my other switches (GS724T no POE) and I dont have this issue.

 

If anyone has an idea (misconfiguration, bug,...) ?

 

Thanks a lot

                                                                         

Model: GS724TP|ProSAFE 24-port Gigabit Smart Switches with PoE
Message 1 of 9

Accepted Solutions
Dariend_Ubiera
Aspirant

Re: DHCP Snooping Block DNS Packet

Hi, that happened to me, what I did to solve the problem was to install the firmware
more recent, since the firmware 1.0.0.24 that brought that switch is the cause of the problem.

View solution in original post

Model: GS724TP|ProSAFE 24-port Gigabit Smart Switches with PoE
Message 8 of 9

All Replies
DaneA
NETGEAR Employee Retired

Re: DHCP Snooping Block DNS Packet

Hi @Arnaud_D,

 

As far as I have checked, there is no issue logged for the GS724TPv2 as per described in your initial post.  Let us try to reflash the firmware.  Here are the steps below:

 

1. Download firmware v1.1.0.24 from this link to your PC.  Make sure to unzip it and save it to your desktop screen.

2. Disconnect your GS724TPv2 from your existing network. 

3. Connect the same PC where you have downloaded firmware v1.1.0.24 to a LAN port of the GS724TPv2.  Set a static IP address of 192.168.0.210 to your PC. 

4. Open a browser like IE or Firefox then at the address bar, type 192.168.0.239 then press Enter. Login to the user interface of switch. Enter "admin" as the username and "password" as the password. 

 

Note: The default IP address of GS724TPv2 is 192.168.0.239. 

 

5. On the web-GUI, go to Maintenance > Download > HTTP File Download.

6. On File Type, select Archive. On Image Name, select image2. 

7. Click Browse then locate the firmware v1.1.0.24 that you have unzipped earlier. 

8. Click Apply. 

 

Note: After a file transfer is started, please wait until the page refreshes. When the page refreshes, the Select File option will be blanked out. This indicates that the upgrade process is done.

 

9. On the web-GUI, go to Maintenance > File Management > Dual Image Configuration.

10. On the image name, select image2 then check the box that says "Activate Image" and click Apply.

11. On the web-GUI, go to Maintenance > Reset > Factory Default.

12. Check the box then click Apply. Wait for the GS724TPv2 to boot up by itself.

 

Note: It is recommended to reset the device back to factory default settings after doing a firmware upgrade/downgrade.  

 

13. On the web-GUI, go to Maintenance > File Management > Dual Image > Dual Image Status.  make sure that image2 is the "current-active" image.

14. Reconfigure the settings from scratch in order to start clean using the firmware uploaded.  Observe if same problem occurs. 

 

 

Regards,

 

DaneA

NETGEAR Community Team

Message 2 of 9
Arnaud_D
Aspirant

Re: DHCP Snooping Block DNS Packet

Hi @DaneA,

 

I did as you said :

 

-DL the firmware

-Factory reset

-Flash the firmware

-I tried to import my previous configuration > same error

-Factory reset N°2

-Minimalist configuration (2 vlans, switch ip, dhcp snooping on/off) > The same problem occurs, as I enable the dhcp filtering > no dns traffic

 

The 3 GS724TP are new, first configurations testing last week.

 

Thx for any further advice

 

 

Message 3 of 9
Hopchen
Prodigy

Re: DHCP Snooping Block DNS Packet

Hi @Arnaud_D

 

Thanks for trying the suggestions by @DaneA. It is always good be on latest FW, etc.

You still have the problem I can see. This is of course not normal behaviour for DHCP snooping. I would like to try and replicate the issue in the lab, today. I will keep you posted.

 


Cheers!

Message 4 of 9
Arnaud_D
Aspirant

Re: DHCP Snooping Block DNS Packet

Hi @Hopchen,

Thx for ur help

(we got the 724tp with the last fw)

Message 5 of 9
Hopchen
Prodigy

Re: DHCP Snooping Block DNS Packet

Hi again,

 

I tested in the lab and I have the same problem as you. I confirmed with a packet capture that the switch allows the DNS request to travel up the network, but the DNS response is blocked. It the exact way that DHCP snooping works, but of course this should not be applied to normal DNS requests.

 

I will need to log this issue to our R&D department. I suggest you use ACLs in the meantime to help combat this. I will send you a PM and we can take it from there.

 


Thanks!

Message 6 of 9
Arnaud_D
Aspirant

Re: DHCP Snooping Block DNS Packet

Thx, i'll reply to ur PM as i get all the informations u asked.

 

Message 7 of 9
Dariend_Ubiera
Aspirant

Re: DHCP Snooping Block DNS Packet

Hi, that happened to me, what I did to solve the problem was to install the firmware
more recent, since the firmware 1.0.0.24 that brought that switch is the cause of the problem.

Model: GS724TP|ProSAFE 24-port Gigabit Smart Switches with PoE
Message 8 of 9
Arnaud_D
Aspirant

Re: DHCP Snooping Block DNS Packet

Hi, thanks for ur answer

Actually I opened a ticket months ago and they informed me that they patched the issue.

The new firmware is now active 🙂

Message 9 of 9
Top Contributors
Discussion stats
  • 8 replies
  • 3397 views
  • 0 kudos
  • 4 in conversation
Announcements