This section contains the DHCP snooping (DHCP_SNOOPING) messages.


Error Message DHCP_SNOOPING-3-DHCP_SNOOPING_INTERNAL_ERROR: DHCP Snooping internal error

Explanation A software sanity check failed in the DHCP snooping process.

Recommended Action This is an informational message only. No action is required.


Error Message DHCP_SNOOPING-4-AGENT_OPERATION_FAILED_N: DHCP snooping binding transfer failed([dec]). [chars]

Explanation This message is logged once every 30 minutes and displays the [dec] number of failures that occurred for a given reason [chars] during the past 30 minutes.

This message is a rate-limited version of the DHCP_SNOOPING-4-AGENT_OPERATION_FAILED message.

Recommended Action Based on the reason for the error [chars], look at the explanation for the DHCP_SNOOPING-4-AGENT_OPERATION_FAILED message, and take the appropriate action.

Error Message DHCP_SNOOPING-4-AGENT_OPERATION_FAILED: DHCP snooping binding transfer failed. Unable to access URL.

Explanation The DHCP snooping binding transfer failed. The reason for failure can include any of the following:

http://www.cisco.com/en/US/i/templates/blank.gifThe URL is not available to use.

http://www.cisco.com/en/US/i/templates/blank.gifNot enough memory is available for creating an agent.

http://www.cisco.com/en/US/i/templates/blank.gifThe number of agents reached the maximum supported limit.

http://www.cisco.com/en/US/i/templates/blank.gifThe switch is unable to create an agent.

http://www.cisco.com/en/US/i/templates/blank.gifThe switch is unable to access the URL.

http://www.cisco.com/en/US/i/templates/blank.gifThe switch is unable to start the agent.

http://www.cisco.com/en/US/i/templates/blank.gifThe Abort timer expired.

http://www.cisco.com/en/US/i/templates/blank.gifThe number of entries exceeded the maximum supported limit.

http://www.cisco.com/en/US/i/templates/blank.gifAn error occurred when reading the remote database.

http://www.cisco.com/en/US/i/templates/blank.gifAn error occurred while writing to the remote database.

http://www.cisco.com/en/US/i/templates/blank.gifDHCP snooping expected more data during the read.

http://www.cisco.com/en/US/i/templates/blank.gifThe string type is invalid.

http://www.cisco.com/en/US/i/templates/blank.gifThe version string type is invalid.

http://www.cisco.com/en/US/i/templates/blank.gifDHCP snooping is expecting a new line in the database.

http://www.cisco.com/en/US/i/templates/blank.gif'TYPE' was not found in the remote database.

http://www.cisco.com/en/US/i/templates/blank.gif'VERSION' was not found in the remote database.

http://www.cisco.com/en/US/i/templates/blank.gif'BEGIN' was not found in the remote database.

http://www.cisco.com/en/US/i/templates/blank.gif'END' was not found in the remote database.

http://www.cisco.com/en/US/i/templates/blank.gifThe type string was not found in the remote database.

http://www.cisco.com/en/US/i/templates/blank.gifThe version string was not found in the remote database.

http://www.cisco.com/en/US/i/templates/blank.gifThe checksum failed upon entry into the remote database.

Recommended Action Based on the reason for the error (listed above), take the appropriate action.

Error Message DHCP_SNOOPING-4-DHCP_SNOOPING_DATABASE_FLASH_WARNING: Saving DHCP snooping bindings to [char] can fill up your device causing the writes of bindings to device

Explanation Saving DHCP snooping bindings to a flash file system such as bootflash or slot0 could cause the flash to fill up. Possible consequences include a long delay to regain a console connection, write failures for database configurations, regular squeeze requirements, and reduced life of flash due to regular squeeze operations.

Recommended Action Save the DHCP snooping bindings to an alternate destination. Possible locations for the database agent include a TFTP or FTP server. Please see the command line help for a complete list of options.

Error Message DHCP_SNOOPING-4-DHCP_SNOOPING_ERRDISABLE_WARNING: DHCP Snooping received [dec] DHCP packets on interface [char]

Explanation DHCP snooping detected a DHCP packet rate-limit violation on the specified interface. The interface will be placed in the errdisable state.

Recommended Action This is an informational message only. No action is required.

Error Message DHCP_SNOOPING-4-DHCP_SNOOPING_PVLAN_WARNING: DHCP Snooping configuration may not take effect on secondary vlan [dec]. [char]

Explanation DHCP snooping configuration on the primary VLAN automatically propagates to all secondary VLANs if private VLANs are enabled.

Recommended Action This is an informational message only. No action is required.

Error Message DHCP_SNOOPING-4-IP_SOURCE_BINDING_PVLAN_WARNING: IP source filter may not take effect on secondary vlan [dec] where IP source binding is configured.


Explanation The IP source filter on the primary VLAN automatically propagates to all secondary VLANs if private VLANs are enabled.

Recommended Action Reconfigure the IP source binding to a known functioning VLAN.

Error Message DHCP_SNOOPING-4-IP_SOURCE_BINDING_NON_EXISTING_VLAN_WARNING: IP source binding is configured on non existing vlan [dec].

Explanation IP source binding was configured on a VLAN that has not yet been configured.

Recommended Action This is an informational message only. No action is required. It may persist unless you define the VLAN in question and then reapply the IP source binding. If you see this message regarding a VLAN that is correctly configured, contact your technical support representative.

Error Message DHCP_SNOOPING-4-NTP_NOT_RUNNING: NTP is not running; reloaded binding lease expiration times are incorrect.

Explanation If the DHCP snooping bindings are loaded by the DHCP snooping database agent and NTP is not running, then the calculated lease duration for the bindings will be incorrect.

Recommended Action Configure NTP on the switch to provide an accurate time and date for the system clock. Then disable and re-enable DHCP snooping to clear the bindings database.

Error Message DHCP_SNOOPING-4-QUEUE_FULL: Fail to enqueue DHCP packet into processing queue: [char]

Explanation DHCP packets are coming into the CPU at a much higher rate than the DHCP snooping process can handle them. These unhandled DHCP packets will be dropped to prevent a denial of service attack.

Recommended Action This is an informational message only. No action is required.

Error Message DHCP_SNOOPING-4-SSO_SYNC_ACK_ERROR:Error is encountered in processing acknowledgement for DHCP snooping binding sync [char]. ack message txn id:[hex]

Explanation There was an error in handling the DHCP synchronization acknowledgement. In most of these cases, the ACK message is ignored.

Recommended Action This is an informational message only. No action is required.

Error Message DHCP_SNOOPING-4-STANDBY_AGENT_OPERATION_FAILED: DHCP snooping binding transfer failed on the Standby Supervisor. [char]

Explanation If the DHCP snooping database supporting SSO is configured as a local device, both supervisor engines will update their database whenever there is an update regarding bindings. This error message is an indication that a snooping database update on the standby supervisor engine failed in the manner mentioned. The most likely cause for these problems is if the snooping database is configured as a slot0 device, but functioning compact flash memory is only present on the active supervisor engine's slot0 while the standby supervisor engine's slot0 is empty or faulty. Possible variations in output include:

"URL not available for use."

"Not enough memory available for creating agent."

"Number of agents reached maximum supported limit."

"Unable to create agent."

"Unable to access URL."

"Unable to start agent."

"Abort timer expiry."

"Number of entries exceeded max supported limit."

"Unable to transfer bindings. Memory allocation failure."

"Error reading the remote database."

"Error writing to remote database."

"Expected more data on read."

"Type string invalid."

"Version string invalid."

"New line expected in database."

"\'TYPE\' not found in remote database."

"\'VERSION\' not found in remote database."

"\'BEGIN \' not found in remote database."

"\'END\' not found in remote database."

"Type string not found in remote database."

"Version string not found in remote database."

"Checksum failed on an entry in remote database."

"No failure recorded."

Recommended Action The switch will continue to function if no action is taken, but the redundancy features will be compromised until both active and standby supervisor engines have working flash memory available. Replace or insert flash memory into the supervisor engine that lacks it if needed.


Error Message DHCP_SNOOPING-6-AGENT_OPERATION_SUCCEEDED: DHCP snooping database [char] succeeded.

Explanation DHCP snooping has successfully read from or written to the database.

Recommended Action This is an informational message only. No action is required.

Error Message DHCP_SNOOPING-5-DHCP_SNOOPING_FAKE_INTERFACE: [char] drop message with mismatched source interface the binding is not updated message type: [char] MAC sa: [mac-addr]

Explanation The DHCP snooping feature has detected a host trying to carry out a denial of service attack on another host in the network. The packet will be dropped.

Recommended Action This is an informational message only. No action is required.

Error Message DHCP_SNOOPING-5-DHCP_SNOOPING_MATCH_MAC_FAIL: [char] drop message because the chaddr doesn't match source mac message type: [char] chaddr: [mac-addr] MAC sa: [mac-addr]

Explanation The DHCP snooping feature attempted MAC address validation and the check failed. There may be a malicious host trying to carry out a denial of service attack on the DHCP server. The packet will be dropped.

Recommended Action This is an informational message only. No action is required.

Error Message DHCP_SNOOPING-5-DHCP_SNOOPING_NONZERO_GIADDR: [char] drop message with non-zero giaddr or option82 value on untrusted port message type: [char] MAC sa: [mac-addr]

Explanation The DHCP snooping feature discovered a DHCP packet with option values not allowed on the untrusted port, indicating some host may be trying to act as a DHCP relay or server. The packet will be dropped.

Recommended Action This is an informational message only. No action is required.

Error Message DHCP_SNOOPING-5-DHCP_SNOOPING_UNTRUSTED_PORT: [char] drop message on untrusted port message type: [char] MAC sa: [mac-addr]

Explanation The DHCP snooping feature discovered certain types of DHCP messages not allowed on the untrusted interface, indicating some host may be trying to act as a DHCP server. The packet will be dropped.

Recommended Action This is an informational message only. No action is required.


Error Message DHCP_SNOOPING-6-AGENT_OPERATION_SUCCEEDED: DHCP snooping database [char] succeeded.

Explanation DHCP snooping has successfully read or written to the database.

Recommended Action This is an informational message only. No action is required.

Error Message DHCP_SNOOPING-6-BINDING_COLLISION: Binding collision. [dec] bindings ignored

Explanation One or more bindings from the database file has a MAC address and VLAN combination for which the switch already holds DHCP snooping bindings.

Recommended Action This is an informational message only. No action is required.

Error Message DHCP_SNOOPING-6-INTERFACE_NOT_VALID: Interface not valid. [dec] bindings ignored.

Explanation The interface that is listed in the database file's binding is not available, that the interface is a router port, or that the interface is a DHCP snooping-trusted Layer 2 interface.

Recommended Action This is an informational message only. No action is required.

Error Message DHCP_SNOOPING-6-LEASE_EXPIRED: Lease Expired. [dec] bindings ignored.

Explanation The DHCP lease expired for the given number of bindings from the database file.

Recommended Action This is an informational message only. No action is required.

Error Message DHCP_SNOOPING-6-PARSE_FAILURE: Parsing failed for [dec] bindings.

Explanation The database read operation failed for the stated number of bindings.

Recommended Action This is an informational message only. No action is required.

Error Message DHCP_SNOOPING-6-VLAN_NOT_SUPPORTED: Vlan not supported. [dec] bindings ignored.

Explanation The VLAN is not supported by DHCP snooping.

Recommended Action This is an informational message only. No action is required.

ARP Snooping Messages

This section contains the ARP snooping message.

Error Message    C4K_ARPSNOOPINGMAN-4-OUTOFRESOURCES: Resources for constructing ACLs are not available.

Explanation Software resources are not available to setup hardware to redirect ARP packets to software. Dynamic ARP inspection will not work if this log message appears.

Recommended Action Unconfigure other TCAM related features to reduce switch memory requirements and reconfigure the ACL.

SW_DAI Messages

This section contains the dynamic ARP inspection (DAIMAN) messages.


Error Message    SW_DAI-4-ACL_DENY: [dec]Invalid ARPs (Req) on [chars], vlan [dec]. 

Explanation The switch received ARP packets that are considered invalid by ARP inspection. The packets are invalid, and their presence indicates that administratively denied packets are in the network. This log message generates when packets have been denied by ACLs either explicitly or implicitly (with static ACL configuration). The presence of these packets indicates possible "man-in-the-middle" attacks in the network.

Recommended Action To stop these messages from generating, find the source host of these packets and stop the host from sending them.

Error Message    SW_DAI-4-DHCP_SNOOPING_DENY: [dec] Invalid ARPs (Req) on [chars], vlan [chars]. 

Explanation The switch received ARP packets that are considered invalid by ARP inspection. The packets are invalid, and their presence may be an indication of "man-in-the-middle" attacks that are attempted in the network. This message is logged when the IP address and MAC address binding for the sender on the received VLAN is not listed in the DHCP snooping database.

Recommended Action To stop these messages from generating, find the source host of these packets and stop the host from sending them.

Error Message    SW_DAI-4-INVALID_ARP: [dec] Invalid ARPs (Req) on [chars], vlan [chars].

Explanation The switch received ARP packets that are considered invalid by ARP inspection. The packets are invalid and do not pass one or more of the source MAC address, destination MAC address, or IP address validation checks. A packet was denied because the source MAC address, destination MAC address, or IP validation failed.

Recommended Action To stop these messages from generating, find the source host of these packets and stop the host from sending them.

Error Message    SW_DAI-4-PACKET_BURST_RATE_EXCEEDED: [dec] packets received in [dec] seconds on [char].

Explanation The switch received [dec] number of ARP packets in the specified burst interval. The interface was in the errdisabled state and the switch received the packets at a rate higher than the configured packet rate for every second over the configured burst interval. The message is logged just before the interface entered the errdisabled state and if the configured burst interval is more than one second.

Recommended Action This is an informational message only. No action is required.

Error Message    SW_DAI-4-PACKET_RATE_EXCEEDED: [dec] packets received in [dec] milliseconds on [char].

Explanation The switch received [dec] number of ARP packets in the specified duration on the given interface above the exceeded packet rate. This message is logged just before the interface entered the errdisabled state and when the burst interval is set to one second.

Recommended Action This is an informational message only. No action is required.

Error Message    SW_DAI-4-SPECIAL_LOG_ENTRY: [dec] Invalid ARP packets [%CC]

Explanation The switch received [dec] number of ARP packets that the ARP inspection considers invalid. The packets are invalid, and their presence may be an indication of "man-in-the-middle" attacks attempted on the network. This message displays when the rate of incoming packets exceed the DAI logging rate.

Recommended Action This is an informational message only. No action is required.


Error Message    SW_DAI-6-ACL_PERMIT: [dec] ARPs (Req) on [chars], vlan [chars].

Explanation The switch received ARP packets that have been permitted because of an ACL match.

Recommended Action This is an informational message only. No action is required.

Error Message    SW_DAI-6-DHCP_SNOOPING_PERMIT: [dec] ARPs (Req) on [chars], vlan [chars]

Explanation The switch received ARP packets that have been permitted because the IP and MAC address for the sender match against the DHCP snooping database for the received VLAN.

Recommended Action This is an informational message only. No action is required.


Blackhattrick blog


DHCP_SNOOPING Messages DHCP_SNOOPING Messages Reviewed by BlackHat on 3:32 AM Rating: 5

No comments:

SastiPrice.com Store

Powered by Blogger.