Skip to main content
kcheng
Staff & Editor
Staff & Editor
May 2, 2025

Technical Tip: FortiGate observing logs for DHCP/DHCP Relay despite interfaces is not enabled with DHCP Server or DHCP Relay Feature

  • May 2, 2025
  • 0 replies
  • 1958 views
Description This article describes the steps to troubleshoot a FortiGate DHCP/DHCPRelay Logs observed under local traffic logs where the interface is not configured with the DHCP Server or DHCP Relay feature.
Scope FortiGate.
Solution
  1. The FortiGate is configured to log all Local traffic logs:
                                                                                            

sleekshot.png

 

  1. There are logs recorded for DHCP/DHCP Relay in Local Traffic Logs, and it was observed on Port2:
                                                                                  

    sleekshot.png

     

     

  2. However, Port2 is not configured to function as a DHCP Server or a DHCP relay agent:
                                                                                   

    sleekshot.png

     

     

  3. Further investigation on the Local Logs indicates that the DHCP/DHCP Relay packets have been dropped by FortiGate:
                                                                                         

sleekshot.png

 

This indicates that DHCP packets were received on FortiGate Port2 from other devices in the network. It is an expected behavior for FortiGate to drop the DHCP packet as the interface has not been enabled with DHCP server feature or DHCP relay agent feature.