DHCP Snoop Events

The following are the events related to DHCP snooping.

Event ID: 850 (Severity: Warning)

Message
<MODULE_NAME>: Server <DHCPv4-SERVER-IP> packet received on untrusted port <PORT_ID> dropped
Platforms K, KA, KB, RA, WB, WC, YA, YB, YC
Category DHCP Snoop
Severity Warning

Event ID: 851 (Severity: Warning)

Message
<MODULE_NAME>: Ceasing untrusted server logs for <TIME>
Platforms K, KA, KB, RA, WB, WC, YA, YB, YC
Category DHCP Snoop
Severity Warning

Event ID: 852 (Severity: Warning)

Message
<MODULE_NAME>: Client packet destined to untrusted port <PORT_ID> dropped
Platforms K, KA, KB, RA, WB, WC, YA, YB, YC
Category DHCP Snoop
Severity Warning
Description BPDU starvation for a VLAN on a port in PVST.

Event ID: 853 (Severity: Warning)

Message
<MODULE_NAME>: Ceasing untrusted port destination logs for <TIME>
Platforms K, KA, KB, RA, WB, WC, YA, YB, YC
Category DHCP Snoop
Severity Warning
Description More than one client unicast packet with an untrusted port destination was dropped. To avoid filling the log file with repeated attempts; untrusted port destination  attempts will not be logged for the specified duration.

Event ID: 854 (Severity: Warning)

Message
<MODULE_NAME>: Unauthorized server <DHCPv4-SERVER-IP> detected on port <PORT_ID>
Platforms K, KA, KB, RA, WB, WC, YA, YB, YC
Category DHCP Snoop
Severity Warning
Description Indicates that an unauthorized DHCP server is attempting to send packets. This event is recognized when a server packet is dropped because it is not configured in the DHCP-snooping authorized server table.

Event ID: 855 (Severity: Warning)

Message
<MODULE_NAME>: Ceasing unauthorized server logs for <TIME>
Platforms K, KA, KB, RA, WB, WC, YA, YB, YC
Category DHCP Snoop
Severity Warning
Description More than one unauthorized server packet was dropped. To avoid filling the log file with repeated attempts; unauthorized server transmit attempts will not be logged for the specified duration.

Event ID: 856 (Severity: Warning)

Message
<MODULE_NAME>: Received untrusted relay info from client <DHCPv4-CLIENT-MAC> on port <PORT_ID>
Platforms K, KA, KB, RA, WB, WC, YA, YB, YC
Category DHCP Snoop
Severity Warning
Description Indicates the reception on an untrusted port of a client packet containing a relay information option field. This event is recognized when a  client packet containing a relay information option field is dropped because  it was received on a port configured as untrusted.

Event ID: 857 (Severity: Warning)

Message
<MODULE_NAME>: Ceasing untrusted relay information logs for <TIME>
Platforms K, KA, KB, RA, WB, WC, YA, YB, YC
Category DHCP Snoop
Severity Warning
Description More than one DHCP client packet received on an untrusted port with a relay info field was dropped. To avoid filling the log file with repeated attempts-untrusted relay info packets will not be logged for the specified duration.

Event ID: 858 (Severity: Warning)

Message
<MODULE_NAME>: client address <DHCPv4_CLIENT_CHADDR> not equal to source MAC <DHCPv4_CLIENT_PACKET_SOURCE_MAC> detected on port <PORT_ID>
Platforms K, KA, KB, RA, WB, WC, YA, YB, YC
Category DHCP Snoop
Severity Warning
Description Indicates that a client packet source MAC address does not match the CHADDR field. This event is recognized when the DHCP-snooping agent is enabled to

Event ID: 859 (Severity: Warning)

Message
<MODULE_NAME>: Ceasing client address mismatch logs for <TIME>
Platforms K, KA, KB, RA, WB, WC, YA, YB, YC
Category DHCP Snoop
Severity Warning
Description More than one DHCP client packet with mismatched source mac and CHADDR field was dropped. To avoid filling the log file with repeated attempts; client address mismatch events will not be logged for the specified duration

Event ID: 860 (Severity: Warning)

Message
<MODULE_NAME>: Attempt to release address DHCPv4-IP leased to port <PORT_ID> detected on port <PORT_ID>
Platforms K, KA, KB, RA, WB, WC, YA, YB, YC
Category DHCP Snoop
Severity Warning
Description Indicates an attempt by a client to release an address when a DHCPRELEASE or DHCPDECLINE packet is received on a port different from the port the address was leased to.

Event ID: 861 (Severity: Warning)

Message
<MODULE_NAME>: Ceasing bad release logs for <TIME>
Platforms K, KA, KB, RA, WB, WC, YA, YB, YC
Category DHCP Snoop
Severity Warning
Description More than one bad DHCP client release packet was dropped. To avoid filling the  log file with repeated bad release dropped packets; bad releases will not be  logged for specified duration.

Event ID: 862 (Severity: Warning)

Message
<MODULE_NAME>: Lease table is full- DHCP lease was not added
Platforms K, KA, KB, RA, WB, WC, YA, YB, YC
Category DHCP Snoop
Severity Warning
Description The lease table is full and this lease will not be added to it.

Event ID: 863 (Severity: Warning)

Message
<MODULE_NAME>: Ceasing lease table is full logs for <TIME>
Platforms K, KA, KB, RA, WB, WC, YA, YB, YC
Category DHCP Snoop
Severity Warning
Description More than one lease was attempted to be added & table is full. To avoid filling  the log file with repeated messages; table full messages will not be logged for specified duration.

Event ID: 864 (Severity: Warning)

Message
<MODULE_NAME>: reading  <TFTP_SERVER_IP>: <FILENAME> <ERROR>
Platforms K, KA, KB, RA, WB, WC, YA, YB, YC
Category DHCP Snoop
Severity Warning
Description The lease file specified by the DHCP snooping database string could not be read.

Event ID: 865 (Severity: Warning)

Message
<MODULE_NAME>: Ceasing remote server lease file read status logs for <TIME>
Platforms K, KA, KB, RA, WB, WC, YA, YB, YC
Category DHCP Snoop
Severity Warning
Description More than one attempt to read the lease file from a remote server was made. To avoid filling the log file with repeated messages; read lease file status messages will not be logged for specified duration.

Event ID: 866 (Severity: Warning)

Message
<MODULE_NAME>: writing  <TFTP_SERVER_IP>: <FILENAME> <ERROR>
Platforms K, KA, KB, RA, WB, WC, YA, YB, YC
Category DHCP Snoop
Severity Warning
Description The lease file specified by the DHCP snooping database string could not be written to the remote server.

Event ID: 867 (Severity: Warning)

Message
<MODULE_NAME>: Ceasing remote server lease file write status logs for <TIME>
Platforms K, KA, KB, RA, WB, WC, YA, YB, YC
Category DHCP Snoop
Severity Warning
Description More than one attempt to write the lease file to a remote server was made. To avoid filling the log file with repeated messages write lease file status messages will not be logged for specified duration.

Event ID: 868 (Severity: Warning)

Message
<MODULE_NAME>: The dynamic binding for DHCPv4-CLIENT-IP on port <PORT_ID> was replaced with a manual binding.
Platforms K, KA, KB, RA, WB, WC, YA, YB, YC
Category DHCP Snoop
Severity Warning
Description DHCP Snooping replaced a learned binding with a manual binding because the lease table was full.

Event ID: 869 (Severity: Warning)

Message
<MODULE_NAME>: Ceasing removed lease logs for <TIME>.
Platforms K, KA, KB, RA, WB, WC, YA, YB, YC
Category DHCP Snoop
Severity Warning
Description A lease was removed from the lease table. Removed lease logs will not be logged for the specified duration.

Event ID: 870 (Severity: Warning)

Message
<MODULE_NAME>: Drop request from <DHCPv4-CLIENT-MAC> for DHCPv4-IP because the address is already assigned to another client
Platforms K, KA, KB, RA, WB, WC, YA, YB, YC
Category DHCP Snoop
Severity Warning
Description The message is generated because the client is requesting an IP address that is already in use by a different client in the same VLAN.

Event ID: 871 (Severity: Warning)

Message
<MODULE_NAME>: Ceasing status logs for Duplicate IP request for <TIME>
Platforms K, KA, KB, RA, WB, WC, YA, YB, YC
Category DHCP Snoop
Severity Warning
Description The message is generated because the client is requesting an IP address that is already in use by a different client in the same VLAN. To avoid filling the log file with repeated messages bad IP request messages will not be logged for specified duration.

Event ID: 2684 (Severity: Warning)

Message
<MODULE_NAME>: Drop offer from <DHCPv4_SERVER_IP> of <DHCPv4_IP> because the address is already assigned to another client
Platforms K, KA, KB, RA, WB, WC, YA, YB, YC
Category DHCP Snoop
Severity Warning
Description The message is generated because the DHCP-server offered an IP address that is already in use by a different client in the same VLAN.

Event ID: 2685 (Severity: Warning)

Message
<MODULE_NAME>: Ceasing status logs for Duplicate IP offers for <TIME>
Platforms K, KA, KB, RA, WB, WC, YA, YB, YC
Category DHCP Snoop
Severity Warning
Description The message is generated because the DHCP-server offered an IP address  that is already in use by a different client in the same VLAN To avoid filling the log file with repeated messages bad IP offer messages will not be logged for specified duration.

Event ID: 2686 (Severity: Warning)

Message
<MODULE_NAME>: Drop offer from <DHCPv4-SERVER-IP> of DHCPv4-IP; address is illegal.
Platforms K, KA, KB, RA, WB, WC, YA, YB, YC
Category DHCP Snoop
Severity Warning
Description DHCP Snooping dropped a packet because it contained illegal lease information.

Event ID: 2687 (Severity: Warning)

Message
<MODULE_NAME>: Ceasing illegal lease information logs for <TIME>.
Platforms K, KA, KB, RA, WB, WC, YA, YB, YC
Category DHCP Snoop
Severity Warning
Description A packet was dropped because it contained illegal lease information. To avoid filling the log file with repeated attempts illegal lease  messages will not be logged for the specified duration.

Event ID: 2688 (Severity: Warning)

Message
  Dhcp-snooping event statistics cleared as a result of 'clear dhcp-snooping statistics' command.
Platforms K, KA, KB, RA, WB, WC, YA, YB, YC
Category DHCP Snoop
Severity Warning

Event ID: 2689 (Severity: Warning)

Message
  Ceasing cleared dhcp-snooping event statistics.
Platforms K, KA, KB, RA, WB, WC, YA, YB, YC
Category DHCP Snoop
Severity Warning

Event ID: 2690 (Severity: Warning)

Message
<MODULE_NAME>: Drop request from <DHCPv4-CLIENT-MAC> for DHCPv4-IP because the max-binding limit has reached on the port <PORT_ID>.
Platforms K, KA, KB, RA, WB, WC, YA, YB, YC
Category DHCP Snoop
Severity Warning
Description A packet was dropped because the configured max-binding limit on the port has been reached.

Event ID: 2691 (Severity: Warning)

Message
<MODULE_NAME>: Ceasing max-binding limit crossed packet information logs for <TIME>.
Platforms K, KA, KB, RA, WB, WC, YA, YB, YC
Category DHCP Snoop
Severity Warning
Description Dropping Packets as the max binding limit has reached for DHCPv4-IP.  To avoid filling the log file with repeated attempts, messages will not be logged for the specified duration.

Event ID: 2692 (Severity: Warning)

Message
<MODULE_NAME>: Max-binding on port <PORT_ID> was removed.
Platforms K, KA, KB, RA, WB, WC, YA, YB, YC
Category DHCP Snoop
Severity Warning

Event ID: 2693 (Severity: Warning)

Message
<MODULE_NAME>: Ceasing Removed maxbinding logs for <TIME>.
Platforms K, KA, KB, RA, WB, WC, YA, YB, YC
Category DHCP Snoop
Severity Warning
Description To avoid filling the log file with repeated attempts messages will not be logged for the specified duration.

Event ID: 2694 (Severity: Warning)

Message
<MODULE_NAME>: Current bindings on the port <PORT_ID> is same as max-binding set.
Platforms K, KA, KB, RA, WB, WC, YA, YB, YC
Category DHCP Snoop
Severity Warning
Description This message indicates that current bindings on the port is same as the maximum binding set.

Event ID: 2695 (Severity: Warning)

Message
<MODULE_NAME>: Ceasing Current bindings equals max-binding logs for <TIME>.
Platforms K, KA, KB, RA, WB, WC, YA, YB, YC
Category DHCP Snoop
Severity Warning
Description To avoid filling the log file with repeated attempts, messages will not be logged for the specified duration.

Event ID: 2696 (Severity: Warning)

Message
<MODULE_NAME>: The port <PORT_ID> exceeded the max-binding configured.
Platforms K, KA, KB, RA, WB, WC, YA, YB, YC
Category DHCP Snoop
Severity Warning
Description This message indicates that port has exceeded the max-bindings configured.

Event ID: 2697 (Severity: Warning)

Message
<MODULE_NAME>: Ceasing port exceeded max-binding logs for <TIME>.
Platforms K, KA, KB, RA, WB, WC, YA, YB, YC
Category DHCP Snoop
Severity Warning
Description To avoid filling the log file with repeated attempts, messages will not be logged for the specified duration.

Event ID: 2698 (Severity: Warning)

Message
<MODULE_NAME>: DHCP packets are dropped at port <PORT_ID> due to high packet rate.
Platforms K, KA, KB, RA, WB, WC, YA, YB, YC
Category DHCP Snoop
Severity Warning
Description DHCP packets are dropped at port due to high packet rate.

Event ID: 2699 (Severity: Warning)

Message
<MODULE_NAME>: Ceasing status logs for DHCP packets dropped due to high packet rate for <TIME>.
Platforms K, KA, KB, RA, WB, WC, YA, YB, YC
Category DHCP Snoop
Severity Warning
Description Ceasing status logs for DHCP packets dropped due to high packet rate for specified duration.

Event ID: 5357 (Severity: Warning)

Message
All the dynamic binding entries were cleared.
Platforms KA, KB, RA, WB, WC, YA, YB, YC
Category DHCP Snoop
Severity Warning
Description When all the dynamic DHCP Snooping bindings are cleared.

Event ID: 5358 (Severity: Warning)

Message
Dynamic binding entry with the IP address <IP_ADDR> was cleared.
Platforms KA, KB, RA, WB, WC, YA, YB, YC
Category DHCP Snoop
Severity Warning
Description When the dynamic DHCP Snooping binding is cleared for the IP Address <IP-ADDR>.

Event ID: 5359 (Severity: Warning)

Message
Dynamic binding entries on the port <PORT_NAME> were cleared.
Platforms KA, KB, RA, WB, WC, YA, YB, YC
Category DHCP Snoop
Severity Warning
Description When all the dynamic DHCP Snooping bindings are cleared on the Port <PORT-NUM>.

Event ID: 5360 (Severity: Warning)

Message
Dynamic binding entries on the VLAN <VLAN_ID> were cleared.
Platforms KA, KB, RA, WB, WC, YA, YB, YC
Category DHCP Snoop
Severity Warning
Description When all the dynamic DHCP Snooping bindings are cleared on VLAN <VLAN-ID>.

Event ID: 5651 (Severity: Warning)

Message
<CLIENT_NAME>: Client broadcast packet on port <PORT_NAME> dropped- as neither trusted port nor DHCP Relay configured on VLAN <VLAN_ID>.
Platforms RA, WB, WC, YA, YB, YC
Category DHCP Snoop
Severity Warning
Description Indicates that the DHCP client broadcast packet is dropped, as it could not be forwarded by DHCP Snooping. This happens if the VLAN does not have either trust ports or DHCP Relay configured.

Event ID: 5652 (Severity: Warning)

Message
<DHCP_CLIENT>: Ceasing client broadcast packet drop logs for <DURATION>.
Platforms RA, WB, WC, YA, YB, YC
Category DHCP Snoop
Severity Warning
Description More than one DHCP client broadcast packet is dropped, as the VLAN on which the packet is received does not have either DHCP Trust ports or DHCP Relay configured. To avoid filling the log file with repeated events, this event will not be logged for the specified <duration>.