The Dell Optiplex 9020 DDOS ICMPv6 Multicast Listener Discovery

awesomo

Gawd
Joined
Mar 20, 2010
Messages
528
I wanted to share a problem I had recently because it was just off the wall ridiculous.

I finally got a specific company to upgrade 13 of their computers to new Optiplex 9020's. Shortly after, they started having weird network occurrences, their Mitel Phones would reset and their wireless access points would keep crashing. All printers and computers plugged into the wall continued to work. By the time I got their during the first occurrence, everything was fine, nothing weird showed up in Wireshark. I ended up replacing the switch as their's was 5 years old and with a weird occurrence like that, I figured it might have been on it's way out.

Fast forward 3-weeks, I get the same call in the morning. Same problems, new switch... This time I jumped on the network right away and fired up Wireshark, to my surprise, There were about 15,000 multicast packets per second being generated by a handful of sources, all Dell computers, ICMPv6 Multicast Listener Discovery. No-way all the new computers had viruses. After nearly a day of digging, I figured it out, whenever these computer were in S1 sleep for a few minutes, THEY WOULD DDOS THE DAMN NETWORK. A bios upgrade later to the new A05 and it appears the issue is resolved, but I'm not 100% sold yet. Something could still be wrong. But this was the first time in my decade of I.T. to run into something as ridiculous as I just had.

This problem also seems to effect any computers with the Intel I217 Network card so this just isn't limited to Dell. Both Intel and Dell really dropped the ball on this one, there are going to be a lot of people out there with this problem with absolutely no idea what's causing it.

Frankly, I am still amazed I was able to figure it out so quickly.
 
Last edited:
Back
Top