SG2005P-PD Switch is the top (by >3x) DNS querier in the entire network!

SG2005P-PD Switch is the top (by >3x) DNS querier in the entire network!

27 Reply
Re:SG2005P-PD Switch is the top (by >3x) DNS querier in the entire network!
2025-02-25 20:50:02 - last edited 2025-02-25 21:01:50

  @Clive_A Here's the visual of the pcap from a little over a minute. I mirrored the uplink of the SG2210MP to a free port connected to a linux host and ran tcpdump on that host for all traffic to/from the SG2210MP host IP. I then analyzed that pcap in wireshark. You can see that indeed the switch is sending DNS quries for the configured NTP host about every 8 seconds (and getting valid responses). On my 192.168.4.0/22 subnet, 6.14 is the DNS server and 4.73 is the SG2210MP switch:

 

 

The only non-DNS traffic in the capture was TLS traffic between the switch and the software controller, and ARP queries/responses.

  1  
  1  
#12
Options
Re:SG2005P-PD Switch is the top (by >3x) DNS querier in the entire network!
2025-02-26 00:57:09

Hi @daubstep 

Thanks for posting in our business forum.

daubstep wrote

  @Clive_A Here's the visual of the pcap from a little over a minute. I mirrored the uplink of the SG2210MP to a free port connected to a linux host and ran tcpdump on that host for all traffic to/from the SG2210MP host IP. I then analyzed that pcap in wireshark. You can see that indeed the switch is sending DNS quries for the configured NTP host about every 8 seconds (and getting valid responses). On my 192.168.4.0/22 subnet, 6.14 is the DNS server and 4.73 is the SG2210MP switch:

 

 

 

The only non-DNS traffic in the capture was TLS traffic between the switch and the software controller, and ARP queries/responses.

This is what I am looking for. That capture indicates the switch indeed sends the DNS for the NTP server you have set.

You've changed the NTP to Cloudflare now. Correct?

That does not look right to me. I've sent this to the test team. It seems that certain models experiencing this. I was not seeing this on the models I tried last time.

  1  
  1  
#13
Options
Re:SG2005P-PD Switch is the top (by >3x) DNS querier in the entire network!
2025-02-26 03:34:54 - last edited 2025-02-26 03:36:52

  @Clive_A 

> You've changed the NTP to Cloudflare now. Correct?

Yes, that is correct - I wanted to rule out anything ntp-server specific. All Omada gear should now be using Cloudflare for NTP, and indeed, I can see more rare DNS resolution from other devices for the ntp domain.

 

> It seems that certain models experiencing this. 

Yes, only my SG2008P and SG2210MP switches are repeatedly querying DNS every ~8 seconds for it.
(I have not recently been using my SG2005P-PD, but I assume, since it was the original offender, that it would also be doing so if currently online - but my many EAPs and my Router seem to only query rarely as expected)

  0  
  0  
#14
Options
Re:SG2005P-PD Switch is the top (by >3x) DNS querier in the entire network!
2025-02-26 05:47:50

Hi @daubstep 

Thanks for posting in our business forum.

daubstep wrote

  @Clive_A 

> You've changed the NTP to Cloudflare now. Correct?

Yes, that is correct - I wanted to rule out anything ntp-server specific. All Omada gear should now be using Cloudflare for NTP, and indeed, I can see more rare DNS resolution from other devices for the ntp domain.

 

> It seems that certain models experiencing this. 

Yes, only my SG2008P and SG2210MP switches are repeatedly querying DNS every ~8 seconds for it.
(I have not recently been using my SG2005P-PD, but I assume, since it was the original offender, that it would also be doing so if currently online - but my many EAPs and my Router seem to only query rarely as expected)

I have requested the dev to explain from the code level. Not sure if there is any change on the latest firmware which made it happen again. Will update you soon as I am updated.

  0  
  0  
#15
Options
Re:SG2005P-PD Switch is the top (by >3x) DNS querier in the entire network!-Solution
2025-03-13 01:19:40 - last edited 2025-03-13 01:19:45

Hi @daubstep

FYI, the next firmware has fixed this issue. See the release note about this.

Omada Switch Pre-Release Firmware Adapting to Omada SDNC 5.15.8.2 (Released on Mar 6th, 2025)

 

Since the US team only provides certain models for testing. I cannot get you a perm link to download it.

I uploaded it in the reply. You can download this one.

File:
SG2005P-PDv1_en_1.0.11_[20250304-rel77614]_up.bin.zipDownload
Recommended Solution
  1  
  1  
#16
Options
Re:SG2005P-PD Switch is the top (by >3x) DNS querier in the entire network!
2025-03-22 16:43:57 - last edited 2025-03-22 16:46:38

  @Clive_A Thank you! Do you know if SG2008P v3.20 and SG2210MP v4.20 firmware is available? The SG2210MP seems to be available for v5 hardware only and SG2008P is not available at all. Unfortunately these are my two switches curently with this issue and I don't have my SG2005P-PD v1.0 running at the moment to test.

  0  
  0  
#17
Options
Re:SG2005P-PD Switch is the top (by >3x) DNS querier in the entire network!
2025-03-24 01:33:37

Hi  @daubstep 

daubstep wrote

  @Clive_A Thank you! Do you know if SG2008P v3.20 and SG2210MP v4.20 firmware is available? The SG2210MP seems to be available for v5 hardware only and SG2008P is not available at all. Unfortunately these are my two switches curently with this issue and I don't have my SG2005P-PD v1.0 running at the moment to test.

See the attachment.

File:
SG2008Pv3_en_3.20.9_[20250304-rel77614]_up.bin.zipDownload
  2  
  2  
#18
Options
Re:SG2005P-PD Switch is the top (by >3x) DNS querier in the entire network!-Solution
2025-03-24 01:34:44 - last edited 2025-03-24 01:35:39

Hi  @daubstep

daubstep wrote

  @Clive_A Thank you! Do you know if SG2008P v3.20 and SG2210MP v4.20 firmware is available? The SG2210MP seems to be available for v5 hardware only and SG2008P is not available at all. Unfortunately these are my two switches curently with this issue and I don't have my SG2005P-PD v1.0 running at the moment to test.

SG2008P V3.20 is posted above this reply in case you missed that.

 

For SG2210MP V4.

These are both pre-release versions. Not the final. You can upgrade to the official once the pre-release phase ends.

File:
SG2210MPv4_en_4.20.10_[20250304-rel77614]_up.bin.zipDownload
Recommended Solution
  1  
  1  
#19
Options
Re:SG2005P-PD Switch is the top (by >3x) DNS querier in the entire network!
2025-03-24 17:22:12

  @Clive_A Thank you!
I updated both switches last night to the attached firmware and my controller now shows:

SG2008P v3.20: 3.20.9 Build 20250304 Rel.77614

SG2210MP v4.20: 4.20.10 Build 20250304 Rel.77614

 

After the update, my SG2210MP does appear to have stopped sending DNS requests for the NTP server hostname, however, my SG2008P continues to send them every ~8seconds. Figure it was worth reporting since it seems the fix is not working for the SG2008P.

 

 

  0  
  0  
#20
Options
Re:SG2005P-PD Switch is the top (by >3x) DNS querier in the entire network!
2025-03-25 01:19:49

Hi @daubstep 

Thanks for posting in our business forum.

daubstep wrote

  @Clive_A Thank you!
I updated both switches last night to the attached firmware and my controller now shows:

SG2008P v3.20: 3.20.9 Build 20250304 Rel.77614

SG2210MP v4.20: 4.20.10 Build 20250304 Rel.77614

 

After the update, my SG2210MP does appear to have stopped sending DNS requests for the NTP server hostname, however, my SG2008P continues to send them every ~8seconds. Figure it was worth reporting since it seems the fix is not working for the SG2008P.

 

 

Reboot it and monitor it for another day?

Let me know if it persists, I might need the Device Info exported from the switch. But will see.

  1  
  1  
#21
Options