DHCP server full with unknown and misformed MAC addresses

%3CLINGO-SUB%20id%3D%22lingo-sub-1085203%22%20slang%3D%22en-US%22%3EDHCP%20server%20full%20with%20unknown%20and%20misformed%20MAC%20addresses%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1085203%22%20slang%3D%22en-US%22%3E%3CP%3EWe're%20seeing%20this%20across%20multiple%20customers%20and%20now%20for%20one%20it's%20causing%20their%20systems%20to%20run%20out%20of%20IPs.%26nbsp%3B%20They%20get%20dozens%20upon%20dozens%20of%20%22Unique%20ID%22%20registrations%20of%20something%20like%3A%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E3139322e3136382e312e31323400%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThese%20ONLY%20show%20up%20after%20doing%20a%20reconcile%20and%20can%20be%20deleted%20but%20can't%20be%20added%20to%20a%20deny%20filter.%26nbsp%3B%20They%20can%20be%20added%20to%20a%20registration%20but%20that%20doesn't%20solve%20the%20problem%20of%20them%20hogging%20IPs%20for%20devices%20that%20simply%20do%20not%20exist.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI've%20found%20a%20ton%20of%20other%20people%20talking%20about%20this%2C%20but%20no%20real%20definitive%20proof%20as%20to%20what's%20happening%20and%20no%20real%20solution%20other%20than%20PHP%20script%20found%20here%3A%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fcamratus.com%2F2017%2F07%2F26%2Fdeal-with-dhcp-server-ip-exhausted%2F%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fcamratus.com%2F2017%2F07%2F26%2Fdeal-with-dhcp-server-ip-exhausted%2F%3C%2FA%3E%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FP%3E%3CP%3EI%20have%20no%20desire%20to%20install%20and%20maintain%20PHP%20on%20every%20Windows%20Server%20nor%20should%20we%20have%20to.%26nbsp%3B%20The%20Powershell%20command%26nbsp%3BExport-DhcpServer%26nbsp%3B%20doesn't%20export%20these%20despite%20being%20shown%20in%20the%20table.%26nbsp%3B%20The%20Powershell%20command%26nbsp%3BGet-DhcpServerv4Lease%20does%20show%20them%2C%20but%20it%20truncates%20them%20to%20have%20...%20at%20the%20end%20of%20the%20normal%20MAC%20length%20which%20means%20I%20can't%20use%26nbsp%3BRemove-DhcpServerv4Lease%20to%20remove%20them%20if%20I%20parse%20the%20output.%26nbsp%3B%20If%20I%20put%20the%20actual%20long%20MAC%20address%20in%20the%26nbsp%3BRemove-DhcpServerv4Lease%20command%20it%20will%20remove%20it%2C%20but%20they%20change%20so%20I%20can't%20just%20build%20a%20list%20and%20run%20it%20as%20a%20scheduled%20task.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EGiven%20the%20plethora%20of%20posts%20and%20complaints%20about%20this%20I%20can't%20understand%20how%201)%20Microsoft%20has%20no%20articles%20I%20can%20find%20on%20it%3B%202)%20Microsoft%20has%20no%20guidance%20on%20how%20fix%2Fstop%20it%3B%203)%20Microsoft%20hasn't%20updated%20DHCP%20on%20either%20Server%202016%20or%202019%20to%20resolve%20the%20issue.%26nbsp%3B%20This%20has%20apparently%20been%20happening%20since%20at%20least%20Server%202008%20R2%2C%20though%20we%20just%20recently%20started%20having%20issues%20with%20it.%3CBR%20%2F%3E%3CBR%20%2F%3EOne%20poster%20here%2C%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fsocial.technet.microsoft.com%2FForums%2Fie%2Fen-US%2Fb5a40949-e6a0-4e9a-aa71-87b4b61d8edd%2F2008-r2-dhcp-server-assigning-addresses-to-unique-ids-like-3139322e3136382e33302e31323800%3Fforum%3Dwinserveripamdhcpdns%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fsocial.technet.microsoft.com%2FForums%2Fie%2Fen-US%2Fb5a40949-e6a0-4e9a-aa71-87b4b61d8edd%2F2008-r2-dhcp-server-assigning-addresses-to-unique-ids-like-3139322e3136382e33302e31323800%3Fforum%3Dwinserveripamdhcpdns%3C%2FA%3E%2C%20said%20they%20traced%20it%20to%20Win7%26nbsp%3B%3CSPAN%3Ewifi%20miniport%20adapter%20but%20in%20all%20instances%20there%20are%20no%20Win7%20machines%20on%20the%20network%20(they're%20all%20Win10%20Pro).%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%3EAnyway%2C%20the%20bigger%20the%20network%2C%20the%20bigger%20the%20problem.%26nbsp%3B%20Small%20LANs%20with%20a%20half%20dozen%20systems%20will%20have%20a%20couple%20in%20them%2C%20while%20larger%20LANs%20with%20dozens%20or%20hundreds%20of%20PCs%20will%20have%20so%20man%20that%20the%20scope%20will%20down%20to%200%25%20available%20IPs.%26nbsp%3B%20At%20this%20point%20with%20one%20client%20with%20about%20140%20devices%20on%20their%20%2F24%2C%20I'm%20going%20to%20have%20to%20convert%20it%20to%20a%20%2F23%20just%20to%20have%20a%20DHCP%20range%20large%20enough%20to%20allow%20these%20registrations.%26nbsp%3B%20I%20just%20want%20them%20stopped.%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%3EBTW%2C%20the%20DHCP%20log%20files%20are%20logging%20exactly%20ZERO%20of%20these%20requests.%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%3EAnyway%2C%20anyone%20have%20any%20idea%20how%20to%20stop%20this%20madness%20without%20having%20to%20either%20do%20it%20manually%20or%20resorting%20to%20PHP%3F%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%3EThanks!%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1085203%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EDHCP%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EManagement%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3ENetworking%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EPowerShell%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EWindows%20Server%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1085819%22%20slang%3D%22en-US%22%3ERe%3A%20DHCP%20server%20full%20with%20unknown%20and%20misformed%20MAC%20addresses%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1085819%22%20slang%3D%22en-US%22%3E%3CP%3EI'd%20suggest%20you%20can%20start%20a%20case%20here%20with%20product%20support.%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fsupport.microsoft.com%2Fen-us%2Fhub%2F4343728%2Fsupport-for-business%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%22%3E%3CFONT%20style%3D%22background-color%3A%20%23ffffff%3B%22%3Ehttps%3A%2F%2Fsupport.microsoft.com%2Fen-us%2Fhub%2F4343728%2Fsupport-for-business%3C%2FFONT%3E%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E%3CFONT%20style%3D%22background-color%3A%20%23ffffff%3B%22%3E%26nbsp%3B%3C%2FFONT%3E%3C%2FP%3E%0A%3CP%3E%3CFONT%20style%3D%22background-color%3A%20%23ffffff%3B%22%3E%26nbsp%3B%3C%2FFONT%3E%3C%2FP%3E%0A%3CP%3E%3CFONT%20style%3D%22background-color%3A%20%23ffffff%3B%22%3E%26nbsp%3B%3C%2FFONT%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
Occasional Contributor

We're seeing this across multiple customers and now for one it's causing their systems to run out of IPs.  They get dozens upon dozens of "Unique ID" registrations of something like:

 

3139322e3136382e312e31323400

 

These ONLY show up after doing a reconcile and can be deleted but can't be added to a deny filter.  They can be added to a registration but that doesn't solve the problem of them hogging IPs for devices that simply do not exist.

 

I've found a ton of other people talking about this, but no real definitive proof as to what's happening and no real solution other than PHP script found here:

https://camratus.com/2017/07/26/deal-with-dhcp-server-ip-exhausted/

I have no desire to install and maintain PHP on every Windows Server nor should we have to.  The Powershell command Export-DhcpServer  doesn't export these despite being shown in the table.  The Powershell command Get-DhcpServerv4Lease does show them, but it truncates them to have ... at the end of the normal MAC length which means I can't use Remove-DhcpServerv4Lease to remove them if I parse the output.  If I put the actual long MAC address in the Remove-DhcpServerv4Lease command it will remove it, but they change so I can't just build a list and run it as a scheduled task.

 

Given the plethora of posts and complaints about this I can't understand how 1) Microsoft has no articles I can find on it; 2) Microsoft has no guidance on how fix/stop it; 3) Microsoft hasn't updated DHCP on either Server 2016 or 2019 to resolve the issue.  This has apparently been happening since at least Server 2008 R2, though we just recently started having issues with it.

One poster here, https://social.technet.microsoft.com/Forums/ie/en-US/b5a40949-e6a0-4e9a-aa71-87b4b61d8edd/2008-r2-dh..., said they traced it to Win7 wifi miniport adapter but in all instances there are no Win7 machines on the network (they're all Win10 Pro).

 

Anyway, the bigger the network, the bigger the problem.  Small LANs with a half dozen systems will have a couple in them, while larger LANs with dozens or hundreds of PCs will have so man that the scope will down to 0% available IPs.  At this point with one client with about 140 devices on their /24, I'm going to have to convert it to a /23 just to have a DHCP range large enough to allow these registrations.  I just want them stopped.

 

BTW, the DHCP log files are logging exactly ZERO of these requests.

 

Anyway, anyone have any idea how to stop this madness without having to either do it manually or resorting to PHP?

 

Thanks!

1 Reply
Highlighted

I'd suggest you can start a case here with product support. 

 

https://support.microsoft.com/en-us/hub/4343728/support-for-business