SG2005P-PD Switch is the top (by >3x) DNS querier in the entire network!
SG2005P-PD Switch is the top (by >3x) DNS querier in the entire network!

I was looking at some DNS stats and noticed one host was by far top of the most DNS lookups list, with more than 3x the next highest host... I was curious and went looking to find out what it was - only to see that it is my SG2005P-PD, doing mltiple DNS lookups of multiple NTP hosts every few seconds - why would it be doing this, and how do I fix it so it stops? Every omada device on the network should have the same NTP config, so it is really odd that this one device is behaving so badly on its own.
Small snapshot of multiple DNS requests for multiple NTP hosts every few seconds from 192.168.4.92
Confirming that 192.168.4.92 is this Omada managed switch:
By far this one switch is dominating DNS lookup, all for these NTP hosts (30% of ALL DNS requests):
My Site NTP config only has the single "time-dot-nist-dot-gov" (using "-dot-" to prevent illegal link blocking) host specified, so I don't even know where it is getting the other "ntp1-dot-glb-dot-nist-dot-gov" NTP hostname from... and it shouldn't be looking up either multiple times a second (it shouldn't be attemptig to sync time multiple times a second either)!
- Copy Link
- Subscribe
- Bookmark
- Report Inappropriate Content
@Clive_A Here's the visual of the pcap from a little over a minute. I mirrored the uplink of the SG2210MP to a free port connected to a linux host and ran tcpdump on that host for all traffic to/from the SG2210MP host IP. I then analyzed that pcap in wireshark. You can see that indeed the switch is sending DNS quries for the configured NTP host about every 8 seconds (and getting valid responses). On my 192.168.4.0/22 subnet, 6.14 is the DNS server and 4.73 is the SG2210MP switch:
The only non-DNS traffic in the capture was TLS traffic between the switch and the software controller, and ARP queries/responses.
- Copy Link
- Report Inappropriate Content
Hi @daubstep
Thanks for posting in our business forum.
daubstep wrote
@Clive_A Here's the visual of the pcap from a little over a minute. I mirrored the uplink of the SG2210MP to a free port connected to a linux host and ran tcpdump on that host for all traffic to/from the SG2210MP host IP. I then analyzed that pcap in wireshark. You can see that indeed the switch is sending DNS quries for the configured NTP host about every 8 seconds (and getting valid responses). On my 192.168.4.0/22 subnet, 6.14 is the DNS server and 4.73 is the SG2210MP switch:
The only non-DNS traffic in the capture was TLS traffic between the switch and the software controller, and ARP queries/responses.
This is what I am looking for. That capture indicates the switch indeed sends the DNS for the NTP server you have set.
You've changed the NTP to Cloudflare now. Correct?
That does not look right to me. I've sent this to the test team. It seems that certain models experiencing this. I was not seeing this on the models I tried last time.
- Copy Link
- Report Inappropriate Content
> You've changed the NTP to Cloudflare now. Correct?
Yes, that is correct - I wanted to rule out anything ntp-server specific. All Omada gear should now be using Cloudflare for NTP, and indeed, I can see more rare DNS resolution from other devices for the ntp domain.
> It seems that certain models experiencing this.
Yes, only my SG2008P and SG2210MP switches are repeatedly querying DNS every ~8 seconds for it.
(I have not recently been using my SG2005P-PD, but I assume, since it was the original offender, that it would also be doing so if currently online - but my many EAPs and my Router seem to only query rarely as expected)
- Copy Link
- Report Inappropriate Content
Hi @daubstep
Thanks for posting in our business forum.
daubstep wrote
> You've changed the NTP to Cloudflare now. Correct?
Yes, that is correct - I wanted to rule out anything ntp-server specific. All Omada gear should now be using Cloudflare for NTP, and indeed, I can see more rare DNS resolution from other devices for the ntp domain.
> It seems that certain models experiencing this.
Yes, only my SG2008P and SG2210MP switches are repeatedly querying DNS every ~8 seconds for it.
(I have not recently been using my SG2005P-PD, but I assume, since it was the original offender, that it would also be doing so if currently online - but my many EAPs and my Router seem to only query rarely as expected)
I have requested the dev to explain from the code level. Not sure if there is any change on the latest firmware which made it happen again. Will update you soon as I am updated.
- Copy Link
- Report Inappropriate Content

Information
Helpful: 0
Views: 581
Replies: 14
Voters 0
No one has voted for it yet.