Rogue End Hosts web page reports false positives
The issue is that dhcp end hosts behind a firewall are reported on the "Potential Rogue DHCP EndHosts" page.
The issue is that the firewall uses multiple interfaces on both the outside and inside. DHCP requests on the inside are getting stored in Infoblox with the MAC of the outward facing NIC in the firewall itself. ARP entries in routers of the DHCP IP and inward facing MAC don't match and the end host is considered rogue.