# AWS EC2 - Rocky Linux 9 - logs flooded with "state changed new lease"

**URL:** https://forums.rockylinux.org/t/aws-ec2-rocky-linux-9-logs-flooded-with-state-changed-new-lease/17359
**Category:** Rocky Linux Help & Support
**Tags:** rocky-linux-9
**Created:** [January 29, 2025, 9:46am UTC](https://forums.rockylinux.org/t/aws-ec2-rocky-linux-9-logs-flooded-with-state-changed-new-lease/17359 "2025-01-29T09:46:01Z")
**Posts on this page:** 16
**Page:** 1

<div class="post-metadata">

### Author: ![nicolabeghin](https://avatars.discourse-cdn.com/v4/letter/n/ee7513/32.png) [@nicolabeghin](https://forums.rockylinux.org/u/nicolabeghin)
#### Post date: [January 29, 2025, 9:46am UTC](https://forums.rockylinux.org/t/aws-ec2-rocky-linux-9-logs-flooded-with-state-changed-new-lease/17359/1 "2025-01-29T09:46:01Z")

</div>

Hi everyone  
on a brand-new Rocky Linux 9 AWS EC2 instance (official image `Rocky-9-EC2-Base-9.5-20241118.0.aarch64-0d51926d-1cd1-4223-bda9-346993accc16` AMI `ami-0793f1de745d09710`) I keep getting the logs flooded by `NetworkManager` with lines like the below

```
dhcp6 (eth0): state changed new lease, address=xyz

```

 ![image](https://us1.discourse-cdn.com/flex020/uploads/rockylinux/original/2X/a/abdff65e1bf3e97bdd0a7f91d759a274c10cc7ad.jpeg)

Any hint about this? Please note: leveraging docker and IPv6.

thanks a lot  
nicola

---

<div class="post-metadata">

### Author: ![iwalker](https://sea2.discourse-cdn.com/flex020/user_avatar/forums.rockylinux.org/iwalker/32/2599_2.png) [@iwalker](https://forums.rockylinux.org/u/iwalker)
#### Post date: [January 29, 2025, 11:27am UTC](https://forums.rockylinux.org/t/aws-ec2-rocky-linux-9-logs-flooded-with-state-changed-new-lease/17359/2 "2025-01-29T11:27:36Z")

</div>

It would suggest dhcp6 is attempting to get an address and not getting one or getting a different one regularly for some reason. If you are not using dhcp6, perhaps edit the network connection to disable IPv6 by setting it to manual?

Or perhaps ask AWS what is going on with dhcp6 at their end, as it could well be a problem with their environment.

---

<div class="post-metadata">

### Author: ![nicolabeghin](https://avatars.discourse-cdn.com/v4/letter/n/ee7513/32.png) [@nicolabeghin](https://forums.rockylinux.org/u/nicolabeghin)
#### Post date: [January 29, 2025, 2:55pm UTC](https://forums.rockylinux.org/t/aws-ec2-rocky-linux-9-logs-flooded-with-state-changed-new-lease/17359/3 "2025-01-29T14:55:46Z")

</div>

thanks @iwalker - IPv6 is mandatory for my purposes (avoiding AWS IPv4 charges, FYI). Any other hint apart from raising an AWS support?

---

<div class="post-metadata">

### Author: ![iwalker](https://sea2.discourse-cdn.com/flex020/user_avatar/forums.rockylinux.org/iwalker/32/2599_2.png) [@iwalker](https://forums.rockylinux.org/u/iwalker)
#### Post date: [January 29, 2025, 3:29pm UTC](https://forums.rockylinux.org/t/aws-ec2-rocky-linux-9-logs-flooded-with-state-changed-new-lease/17359/4 "2025-01-29T15:29:28Z")

</div>

Sadly not, I have a server with OVH and I don’t have these messages, so would suggest it’s a problem with their configuration.

---

<div class="post-metadata">

### Author: ![Hedges](https://avatars.discourse-cdn.com/v4/letter/h/58f4c7/32.png) [@Hedges](https://forums.rockylinux.org/u/Hedges)
#### Post date: [January 30, 2025, 5:00pm UTC](https://forums.rockylinux.org/t/aws-ec2-rocky-linux-9-logs-flooded-with-state-changed-new-lease/17359/5 "2025-01-30T17:00:20Z")

</div>

You can check the lease expire date for the DHCP6 leases you get. May be they are really short (instead of the common default of 24h).  
You can try this ( replace DHCP4 with DHCP6 and “enp1s0” with “eth0”):

```auto
[root@localhost ~]# nmcli -f DHCP4 dev show enp1s0 |grep -i exp
DHCP4.OPTION[6]: expiry = 1738258354
[root@localhost ~]# date -d "@1738258354"
Thu Jan 30 06:32:34 PM CET 2025
[root@localhost ~]#

```

If you cannot find the reason for those messages but want to suppress them, you can reconfigure rsyslogd via configuration file /etc/rsyslog.conf to not log the “info” level of facility “daemon” to /var/log/messages anymore.  
Rocky 9 has this line:  
`*.info;mail.none;authpriv.none;cron.none /var/log/messages`  
To ignore info level for all daemon processes ( including NetworkManager)  
and start logging with next higher level “notice” this might work:  
`*.info;mail.none;authpriv.none;cron.none;daemon.notice /var/log/messages`

( appending “daemon.notice” should overwrite “\*.info” from the first entry. There might be better ways to do this with advanced rsyslog filtering, e.g. by only ignoring messages with text “changed new lease”)

In my daily work we see many different reasons why processes are spamming our log files and often we cannot change that behaviour. So a common thing we do is to enable “logrotate” to run every day. This way our logs are rotated and compressed.

---

<div class="post-metadata">

### Author: ![nicolabeghin](https://avatars.discourse-cdn.com/v4/letter/n/ee7513/32.png) [@nicolabeghin](https://forums.rockylinux.org/u/nicolabeghin)
#### Post date: [January 30, 2025, 5:46pm UTC](https://forums.rockylinux.org/t/aws-ec2-rocky-linux-9-logs-flooded-with-state-changed-new-lease/17359/6 "2025-01-30T17:46:06Z")

</div>

> [@Hedges](#):
>
> You can try this ( replace DHCP4 with DHCP6 and “enp1s0” with “eth0”):

Thanks a lot for your feedback! don’t know if something is truly broken or not, but the IPv6 output from

```
nmcli -f DHCP6 dev show eth0

```

is really short

```
DHCP6.OPTION[1]: dhcp6_client_id = xyz
DHCP6.OPTION[2]: iaid = 2b:50:67:35
DHCP6.OPTION[3]: ip6_address = xxx

```

Is this supposed to be?? The IPv4 is 17 lines long indeed and having the `expiry` field

```
expiry = 1738263024

```

BTW just replicated this with a brand new EC2 instance just to try out: issue happens immediately at first boot, without any docker or anything else installed. Therefore I assume it’s something embedded in the official Rocky image when IPv6 is used.

thanks  
nicola

---

<div class="post-metadata">

### Author: ![iwalker](https://sea2.discourse-cdn.com/flex020/user_avatar/forums.rockylinux.org/iwalker/32/2599_2.png) [@iwalker](https://forums.rockylinux.org/u/iwalker)
#### Post date: [January 30, 2025, 7:34pm UTC](https://forums.rockylinux.org/t/aws-ec2-rocky-linux-9-logs-flooded-with-state-changed-new-lease/17359/7 "2025-01-30T19:34:24Z")

</div>

If the lease is short, then the lease is configured on the DHCP server - which is obviously what AWS manages. Your Rocky image is just a DHCP client that obtains an address from that server. This is why I believe the Rocky image isn’t the problem here, but the DHCP server providing the address. You really need to be talking to AWS about this.

It would help seeing the data/time from your logs as well to see how often the messages are appearing in the log. Your screenshot above doesn’t include that.

---

<div class="post-metadata">

### Author: ![Hedges](https://avatars.discourse-cdn.com/v4/letter/h/58f4c7/32.png) [@Hedges](https://forums.rockylinux.org/u/Hedges)
#### Post date: [January 30, 2025, 7:51pm UTC](https://forums.rockylinux.org/t/aws-ec2-rocky-linux-9-logs-flooded-with-state-changed-new-lease/17359/8 "2025-01-30T19:51:59Z")

</div>

The timestamps in the log look like epoch numbers, so there is a message every 60-70 seconds i think …

---

<div class="post-metadata">

### Author: ![iwalker](https://sea2.discourse-cdn.com/flex020/user_avatar/forums.rockylinux.org/iwalker/32/2599_2.png) [@iwalker](https://forums.rockylinux.org/u/iwalker)
#### Post date: [January 30, 2025, 8:02pm UTC](https://forums.rockylinux.org/t/aws-ec2-rocky-linux-9-logs-flooded-with-state-changed-new-lease/17359/9 "2025-01-30T20:02:09Z")

</div>

Yeah good catch, didn’t realise those numbers to think about checking them, but on [epochconvert.com](http://epochconvert.com) it checks out:

```auto
1738143713.6562 09:41:53.656
1738143771.2992 09:42:51.299

```

---

<div class="post-metadata">

### Author: ![nicolabeghin](https://avatars.discourse-cdn.com/v4/letter/n/ee7513/32.png) [@nicolabeghin](https://forums.rockylinux.org/u/nicolabeghin)
#### Post date: [January 30, 2025, 9:38pm UTC](https://forums.rockylinux.org/t/aws-ec2-rocky-linux-9-logs-flooded-with-state-changed-new-lease/17359/10 "2025-01-30T21:38:53Z")

</div>

I confirm

- it’s around every minute
- this happens with a brand new official Rocky-provided ABI image (just fire up the instance and here it is)
- I tried to raise a bug to Rocky but I cannot even access the register page for [https://bugs.rockylinux.org/](https://bugs.rockylinux.org/) - asked in [chats.rockylinux.org](http://chats.rockylinux.org) if it’s a temporary issue

I have no way to contact AWS since don’t have a support plan at the moment (still evaluating before making the switch).

All in all, I see no light at the end of the tunnel because I’m not aware of DHCP settings I could access on AWS side 😅

---

<div class="post-metadata">

### Author: ![iwalker](https://sea2.discourse-cdn.com/flex020/user_avatar/forums.rockylinux.org/iwalker/32/2599_2.png) [@iwalker](https://forums.rockylinux.org/u/iwalker)
#### Post date: [January 31, 2025, 8:12am UTC](https://forums.rockylinux.org/t/aws-ec2-rocky-linux-9-logs-flooded-with-state-changed-new-lease/17359/11 "2025-01-31T08:12:39Z")

</div>

> [@nicolabeghin](#):
>
> All in all, I see no light at the end of the tunnel because I’m not aware of DHCP settings I could access on AWS side 😅

Yes true, it would require AWS to check it. I’m curious, if you can test another image other than Rocky, say CentOS or Alma if they have it and see if they also have the same problem with Network Manager and IPv6? If they do it would suggest it’s not specific to Rocky as such if other images suffer the same problem. If they don’t suffer the same problem, then it would suggest a problem with the Rocky one.

---

<div class="post-metadata">

### Author: ![nicolabeghin](https://avatars.discourse-cdn.com/v4/letter/n/ee7513/32.png) [@nicolabeghin](https://forums.rockylinux.org/u/nicolabeghin)
#### Post date: [January 31, 2025, 1:35pm UTC](https://forums.rockylinux.org/t/aws-ec2-rocky-linux-9-logs-flooded-with-state-changed-new-lease/17359/12 "2025-01-31T13:35:11Z")

</div>

> [@iwalker](#):
>
> if you can test another image other than Rocky, say CentOS or Alma if they have it and see if they also have the same problem with Network Manager and IPv6

I confirm the same happens with AlmaLinux as well (AMI `AlmaLinux OS 9.5.20241122 aarch64-2d219cc1-aa44-4a1e-b6fe-258d4ebd3cdb`)

---

<div class="post-metadata">

### Author: ![iwalker](https://sea2.discourse-cdn.com/flex020/user_avatar/forums.rockylinux.org/iwalker/32/2599_2.png) [@iwalker](https://forums.rockylinux.org/u/iwalker)
#### Post date: [January 31, 2025, 1:52pm UTC](https://forums.rockylinux.org/t/aws-ec2-rocky-linux-9-logs-flooded-with-state-changed-new-lease/17359/13 "2025-01-31T13:52:10Z")

</div>

Maybe this helps:

> **[Announcing new Amazon VPC DHCPv6 setting to adjust IPv6 preferred lease time](https://aws.amazon.com/about-aws/whats-new/2024/03/amazon-vpc-dhcpv6-setting-ipv6-lease-time/)**

> **[Work with DHCP option sets - Amazon Virtual Private Cloud](https://docs.aws.amazon.com/vpc/latest/userguide/DHCPOptionSet.html#CreatingaDHCPOptionSet)**
>
> Use the following procedures to view and work with DHCP option sets. For more information about how DHCP option sets work, see .

---

<div class="post-metadata">

### Author: ![nicolabeghin](https://avatars.discourse-cdn.com/v4/letter/n/ee7513/32.png) [@nicolabeghin](https://forums.rockylinux.org/u/nicolabeghin)
#### Post date: [January 31, 2025, 2:34pm UTC](https://forums.rockylinux.org/t/aws-ec2-rocky-linux-9-logs-flooded-with-state-changed-new-lease/17359/14 "2025-01-31T14:34:44Z")

</div>

> [@iwalker](#):
>
> Maybe this helps: [Announcing new Amazon VPC DHCPv6 setting to adjust IPv6 preferred lease time](https://aws.amazon.com/about-aws/whats-new/2024/03/amazon-vpc-dhcpv6-setting-ipv6-lease-time/)

I think you’re right (I even remember I stumbled upon that page but discarded on the spot given the Nitro reference). The relevant part is

> By default, the **IPv6 preferred lease time is 140 seconds** and DHCP lease renewals for IPv6 address assignments **occur at the halfway mark of 70 seconds**

therefore it makes sense seeing logs around every minute or so (precisely, every 70 seconds).

This is for sure something not clear from AWS console `VPC -> DHCP option sets` where no such default 140s default lease time is reported and cannot be changed at all in the existing DHCP config set (no edit button at all):

 ![image](https://us1.discourse-cdn.com/flex020/uploads/rockylinux/original/2X/9/982fd41a7c12a2647063354764f32d9897899470.png)

but you can set the IPv6 DHCP lease time for a brand new DHCP config set!

 ![image](https://us1.discourse-cdn.com/flex020/uploads/rockylinux/original/2X/9/9f74bbab0d62a91c402a4520de569529d7e95ce3.png)

Due to this, I think we can consider closed the issue!

thanks again @iwalker @Hedges

---

<div class="post-metadata">

### Author: ![iwalker](https://sea2.discourse-cdn.com/flex020/user_avatar/forums.rockylinux.org/iwalker/32/2599_2.png) [@iwalker](https://forums.rockylinux.org/u/iwalker)
#### Post date: [January 31, 2025, 2:55pm UTC](https://forums.rockylinux.org/t/aws-ec2-rocky-linux-9-logs-flooded-with-state-changed-new-lease/17359/15 "2025-01-31T14:55:31Z")

</div>

Yeah you prob cannot edit the default one, but create your own to override the default.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/flex020/uploads/rockylinux/original/1X/91b7219eec10e30013422e4df76c1d898711a5d5.svg) [@system](https://forums.rockylinux.org/u/system)
#### Post date: [April 1, 2025, 2:55pm UTC](https://forums.rockylinux.org/t/aws-ec2-rocky-linux-9-logs-flooded-with-state-changed-new-lease/17359/16 "2025-04-01T14:55:37Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.
