SG2005P-PD Switch is the top (by >3x) DNS querier in the entire network!

SG2005P-PD Switch is the top (by >3x) DNS querier in the entire network!

27 Reply
Re:SG2005P-PD Switch is the top (by >3x) DNS querier in the entire network!
2025-02-25 20:50:02 - last edited 2025-02-25 21:01:50

  @Clive_A Here's the visual of the pcap from a little over a minute. I mirrored the uplink of the SG2210MP to a free port connected to a linux host and ran tcpdump on that host for all traffic to/from the SG2210MP host IP. I then analyzed that pcap in wireshark. You can see that indeed the switch is sending DNS quries for the configured NTP host about every 8 seconds (and getting valid responses). On my 192.168.4.0/22 subnet, 6.14 is the DNS server and 4.73 is the SG2210MP switch:

 

 

The only non-DNS traffic in the capture was TLS traffic between the switch and the software controller, and ARP queries/responses.

  1  
  1  
#12
Options
Re:SG2005P-PD Switch is the top (by >3x) DNS querier in the entire network!
2025-02-26 00:57:09

Hi @daubstep 

Thanks for posting in our business forum.

daubstep wrote

  @Clive_A Here's the visual of the pcap from a little over a minute. I mirrored the uplink of the SG2210MP to a free port connected to a linux host and ran tcpdump on that host for all traffic to/from the SG2210MP host IP. I then analyzed that pcap in wireshark. You can see that indeed the switch is sending DNS quries for the configured NTP host about every 8 seconds (and getting valid responses). On my 192.168.4.0/22 subnet, 6.14 is the DNS server and 4.73 is the SG2210MP switch:

 

 

 

The only non-DNS traffic in the capture was TLS traffic between the switch and the software controller, and ARP queries/responses.

This is what I am looking for. That capture indicates the switch indeed sends the DNS for the NTP server you have set.

You've changed the NTP to Cloudflare now. Correct?

That does not look right to me. I've sent this to the test team. It seems that certain models experiencing this. I was not seeing this on the models I tried last time.

Best Regards! If you are new to the forum, please read: Howto - A Guide to Use Forum Effectively. Read Before You Post. Look for a model? Search your model NOW Official and Beta firmware. NEW features! Subscribe for the latest update!Download Beta Here☚ ☛ ★ Configuration Guide ★ ☚ ☛ ★ Knowledge Base ★ ☚ ☛ ★ Troubleshooting ★ ☚ ● Be kind and nice. ● Stay on the topic. ● Post details. ● Search first. ● Please don't take it for granted. ● No email confidentiality should be violated. ● S/N, MAC, and your true public IP should be mosaiced.
  1  
  1  
#13
Options
Re:SG2005P-PD Switch is the top (by >3x) DNS querier in the entire network!
2025-02-26 03:34:54 - last edited 2025-02-26 03:36:52

  @Clive_A 

> You've changed the NTP to Cloudflare now. Correct?

Yes, that is correct - I wanted to rule out anything ntp-server specific. All Omada gear should now be using Cloudflare for NTP, and indeed, I can see more rare DNS resolution from other devices for the ntp domain.

 

> It seems that certain models experiencing this. 

Yes, only my SG2008P and SG2210MP switches are repeatedly querying DNS every ~8 seconds for it.
(I have not recently been using my SG2005P-PD, but I assume, since it was the original offender, that it would also be doing so if currently online - but my many EAPs and my Router seem to only query rarely as expected)

  0  
  0  
#14
Options
Re:SG2005P-PD Switch is the top (by >3x) DNS querier in the entire network!
2025-02-26 05:47:50

Hi @daubstep 

Thanks for posting in our business forum.

daubstep wrote

  @Clive_A 

> You've changed the NTP to Cloudflare now. Correct?

Yes, that is correct - I wanted to rule out anything ntp-server specific. All Omada gear should now be using Cloudflare for NTP, and indeed, I can see more rare DNS resolution from other devices for the ntp domain.

 

> It seems that certain models experiencing this. 

Yes, only my SG2008P and SG2210MP switches are repeatedly querying DNS every ~8 seconds for it.
(I have not recently been using my SG2005P-PD, but I assume, since it was the original offender, that it would also be doing so if currently online - but my many EAPs and my Router seem to only query rarely as expected)

I have requested the dev to explain from the code level. Not sure if there is any change on the latest firmware which made it happen again. Will update you soon as I am updated.

Best Regards! If you are new to the forum, please read: Howto - A Guide to Use Forum Effectively. Read Before You Post. Look for a model? Search your model NOW Official and Beta firmware. NEW features! Subscribe for the latest update!Download Beta Here☚ ☛ ★ Configuration Guide ★ ☚ ☛ ★ Knowledge Base ★ ☚ ☛ ★ Troubleshooting ★ ☚ ● Be kind and nice. ● Stay on the topic. ● Post details. ● Search first. ● Please don't take it for granted. ● No email confidentiality should be violated. ● S/N, MAC, and your true public IP should be mosaiced.
  0  
  0  
#15
Options
Re:SG2005P-PD Switch is the top (by >3x) DNS querier in the entire network!-Solution
3 weeks ago - last edited 3 weeks ago

Hi @daubstep

FYI, the next firmware has fixed this issue. See the release note about this.

Omada Switch Pre-Release Firmware Adapting to Omada SDNC 5.15.8.2 (Released on Mar 6th, 2025)

 

Since the US team only provides certain models for testing. I cannot get you a perm link to download it.

I uploaded it in the reply. You can download this one.

File:
SG2005P-PDv1_en_1.0.11_[20250304-rel77614]_up.bin.zipDownload
Best Regards! If you are new to the forum, please read: Howto - A Guide to Use Forum Effectively. Read Before You Post. Look for a model? Search your model NOW Official and Beta firmware. NEW features! Subscribe for the latest update!Download Beta Here☚ ☛ ★ Configuration Guide ★ ☚ ☛ ★ Knowledge Base ★ ☚ ☛ ★ Troubleshooting ★ ☚ ● Be kind and nice. ● Stay on the topic. ● Post details. ● Search first. ● Please don't take it for granted. ● No email confidentiality should be violated. ● S/N, MAC, and your true public IP should be mosaiced.
Recommended Solution
  1  
  1  
#16
Options
Re:SG2005P-PD Switch is the top (by >3x) DNS querier in the entire network!
a week ago - last edited a week ago

  @Clive_A Thank you! Do you know if SG2008P v3.20 and SG2210MP v4.20 firmware is available? The SG2210MP seems to be available for v5 hardware only and SG2008P is not available at all. Unfortunately these are my two switches curently with this issue and I don't have my SG2005P-PD v1.0 running at the moment to test.

  0  
  0  
#17
Options
Re:SG2005P-PD Switch is the top (by >3x) DNS querier in the entire network!
a week ago

Hi  @daubstep 

daubstep wrote

  @Clive_A Thank you! Do you know if SG2008P v3.20 and SG2210MP v4.20 firmware is available? The SG2210MP seems to be available for v5 hardware only and SG2008P is not available at all. Unfortunately these are my two switches curently with this issue and I don't have my SG2005P-PD v1.0 running at the moment to test.

See the attachment.

File:
SG2008Pv3_en_3.20.9_[20250304-rel77614]_up.bin.zipDownload
Best Regards! If you are new to the forum, please read: Howto - A Guide to Use Forum Effectively. Read Before You Post. Look for a model? Search your model NOW Official and Beta firmware. NEW features! Subscribe for the latest update!Download Beta Here☚ ☛ ★ Configuration Guide ★ ☚ ☛ ★ Knowledge Base ★ ☚ ☛ ★ Troubleshooting ★ ☚ ● Be kind and nice. ● Stay on the topic. ● Post details. ● Search first. ● Please don't take it for granted. ● No email confidentiality should be violated. ● S/N, MAC, and your true public IP should be mosaiced.
  2  
  2  
#18
Options
Re:SG2005P-PD Switch is the top (by >3x) DNS querier in the entire network!-Solution
a week ago - last edited a week ago

Hi  @daubstep

daubstep wrote

  @Clive_A Thank you! Do you know if SG2008P v3.20 and SG2210MP v4.20 firmware is available? The SG2210MP seems to be available for v5 hardware only and SG2008P is not available at all. Unfortunately these are my two switches curently with this issue and I don't have my SG2005P-PD v1.0 running at the moment to test.

SG2008P V3.20 is posted above this reply in case you missed that.

 

For SG2210MP V4.

These are both pre-release versions. Not the final. You can upgrade to the official once the pre-release phase ends.

File:
SG2210MPv4_en_4.20.10_[20250304-rel77614]_up.bin.zipDownload
Best Regards! If you are new to the forum, please read: Howto - A Guide to Use Forum Effectively. Read Before You Post. Look for a model? Search your model NOW Official and Beta firmware. NEW features! Subscribe for the latest update!Download Beta Here☚ ☛ ★ Configuration Guide ★ ☚ ☛ ★ Knowledge Base ★ ☚ ☛ ★ Troubleshooting ★ ☚ ● Be kind and nice. ● Stay on the topic. ● Post details. ● Search first. ● Please don't take it for granted. ● No email confidentiality should be violated. ● S/N, MAC, and your true public IP should be mosaiced.
Recommended Solution
  1  
  1  
#19
Options
Re:SG2005P-PD Switch is the top (by >3x) DNS querier in the entire network!
a week ago

  @Clive_A Thank you!
I updated both switches last night to the attached firmware and my controller now shows:

SG2008P v3.20: 3.20.9 Build 20250304 Rel.77614

SG2210MP v4.20: 4.20.10 Build 20250304 Rel.77614

 

After the update, my SG2210MP does appear to have stopped sending DNS requests for the NTP server hostname, however, my SG2008P continues to send them every ~8seconds. Figure it was worth reporting since it seems the fix is not working for the SG2008P.

 

 

  0  
  0  
#20
Options
Re:SG2005P-PD Switch is the top (by >3x) DNS querier in the entire network!
a week ago

Hi @daubstep 

Thanks for posting in our business forum.

daubstep wrote

  @Clive_A Thank you!
I updated both switches last night to the attached firmware and my controller now shows:

SG2008P v3.20: 3.20.9 Build 20250304 Rel.77614

SG2210MP v4.20: 4.20.10 Build 20250304 Rel.77614

 

After the update, my SG2210MP does appear to have stopped sending DNS requests for the NTP server hostname, however, my SG2008P continues to send them every ~8seconds. Figure it was worth reporting since it seems the fix is not working for the SG2008P.

 

 

Reboot it and monitor it for another day?

Let me know if it persists, I might need the Device Info exported from the switch. But will see.

Best Regards! If you are new to the forum, please read: Howto - A Guide to Use Forum Effectively. Read Before You Post. Look for a model? Search your model NOW Official and Beta firmware. NEW features! Subscribe for the latest update!Download Beta Here☚ ☛ ★ Configuration Guide ★ ☚ ☛ ★ Knowledge Base ★ ☚ ☛ ★ Troubleshooting ★ ☚ ● Be kind and nice. ● Stay on the topic. ● Post details. ● Search first. ● Please don't take it for granted. ● No email confidentiality should be violated. ● S/N, MAC, and your true public IP should be mosaiced.
  1  
  1  
#21
Options