2 NIC setup -Very high ARP broadcast packets on nic 1 (domain network). 2nd nic is Camera network (vlan) -

nbabucks1

n3wb
Aug 8, 2023
5
5
usa
Running Blue Iris on new computer - i5-12xxx.
I have 2 nic's.

NIC 1 - Connected to my default network on domain. Used to access the computer via RDP and as web server to login to cameras through firewall port forwarding. Grabs IP via DHCP. ip: 11.100.60.41, subnet 255.255.0.0, dg 11.100.1.1.
NIC 2 - Separate vlan. 192.168.100.x , Subnet 255.255.255.0, DG: Left blank Used to talk to all cameras.

The issue is I am getting NON STOP (thousands of requests in a few seconds) Broadcast traffic ARP (wireshark) from Blue Iris on the 'default network' (nic 1) looking for all the cameras in the subnet (ever single ip from 192.168.100.1 - 192.168.100. 255, as well as 10.100.60.1 - 10.100.60.255) (the IP addresses of 'default network are class A I know, I inherited this network).

Note this only happens when the Blue Iris Service is running. If I kill Blue Iris (service, app) all the ARP broadcast packets in wireshark go away.

How do I keep this traffic off of my 'default network'/ NIC 1. I'd like to be able to still access the web server.
Thanks!
 
Yes it's Blue Iris. I kill the Blue Iris service in services.msc and all the ARP broadcast requests go away and it's normal traffic on the NIC 1 (class B network).

Blue Iris box has 2 NIC's. So yes Blue Iris computer is on NIC 1, but it's also has another NIC 2.

I'm asking how do I stop Blue Iris from flooding my network with ARP requests.

For reference here is my network Wireshark traffic overnight. 300 devices. I connected blue iris to the 'default domain network' (NIC 1 - non camera) twice. See if you can figure out when i did that?



I have emailed them and will go from there. Thanks mate
 

Attachments

  • MicrosoftTeams-image (12).png
    MicrosoftTeams-image (12).png
    54 KB · Views: 8
  • Like
Reactions: Fake News
is there a way to park my blue iris install to only use nic 2?

Blue Iris is on nightly/bleeding edge update - was on last stable about 2 hours ago.

The issue is that when I connect Blue Iris to my network it completly saturates it with ARP requests that flood it and take some devices offline and makes my Wireless access points go haywire. I have 300 devices on my network, 500 during the day. No other device does this.
 
Last edited:
You are talking about restricting at the application layer. I think, any program like BI will try to use any NIC. Especially a NIC with a valid gateway IP (NIC 1).

Only way I can see this working is at the router level. Setting up rules or an access control list blocking BI traffic off NIC 1.

You know WIFI is half duplex right? Don't care how much it costs or what brand, half duplex. Then you tax on 500 users, little congestion there. It's a round robin wait your turn game with WIFI. Another reason hard wired is better. Cheaper, more secure, uses zero electricty blah blah........

I would get off the latest and greatest BI update.

I would get a cheap used machine and put BI and only BI on it. Don't know how many cams you have.

Don't tell us you have one access point? LOL o_O


lol BI is hardwired (all cams wired) on dedicated box I just made i5-12xxx processor . 10 access points, 10 switches all have 10gb spf+ backhaul. Cameras on dedicated vlan.
 
  • Like
Reactions: Fake News
Running Blue Iris on new computer - i5-12xxx.
I have 2 nic's.

NIC 1 - Connected to my default network on domain. Used to access the computer via RDP and as web server to login to cameras through firewall port forwarding. Grabs IP via DHCP. ip: 11.100.60.41, subnet 255.255.0.0, dg 11.100.1.1.
NIC 2 - Separate vlan. 192.168.100.x , Subnet 255.255.255.0, DG: Left blank Used to talk to all cameras.

The issue is I am getting NON STOP (thousands of requests in a few seconds) Broadcast traffic ARP (wireshark) from Blue Iris on the 'default network' (nic 1) looking for all the cameras in the subnet (ever single ip from 192.168.100.1 - 192.168.100. 255, as well as 10.100.60.1 - 10.100.60.255) (the IP addresses of 'default network are class A I know, I inherited this network).

Note this only happens when the Blue Iris Service is running. If I kill Blue Iris (service, app) all the ARP broadcast packets in wireshark go away.

How do I keep this traffic off of my 'default network'/ NIC 1. I'd like to be able to still access the web server.
Thanks!
In BI in each cameras video > configure tab check skip initial reachability tests...