Skip to main content
FortiSpain
Explorer
April 22, 2026
Question

DHCP / DNS ISSUES

  • April 22, 2026
  • 3 replies
  • 137 views

Hi ti all,

 

Our FortiGate 50G is protecting 2 different routers from 2 different ISPs. One is plugged to Wan and the other to Lan1 (=Wan2). Domestic use network. Only ethernet. No WiFi.

 

A few days ago, I tried to protect a TV decoder with the FortiGate. Creating the multicast policies, I have surely changed something I should not have to. The TV decoder was plugged into lan 2 which belongs to a Vlan switch (called "lan". Members: lan 2 + lan 3). This Vlan provides internet from only one of the routers Now I have the following symptoms:

 

- When using this routers's internet and plugging the ethernet cable to my computer, my Airbook gets an auto-assigned IP first (yellow led) and, after 30 seconds, it switches to a normal IP (green led): Internet is available then. This symptom happens only with one of the routers (plugged to lan2 or lan3... Where the TV decoder was plugged to). I tried to disconnect "STP". then the symptom disappears. But comparing with the old configuration file, I noticed that STP was always turned on. So the problem can not come from there. When I am plugged to "A" (internet provided by the other router), this symptom disappears (direct to green led)... The TV decoder was never plugged to "A".

 

- I am unable to connect to ProtonVPN: the app says that their servers are unreachable due to DNS problems or configuration issues. Sometimes the app says that the password is not correct (which is not the case). This symptom happens with both routers. I have deleted Proton VPN like 4 times (with all the remaining files) but the results are always the same. At this time, I can not use it.

 

The  multicast policies have been deleted.

 

Thank you very much for your help. 

3 replies

FortiSpain
Explorer
May 5, 2026

@AEK ​@mpapisetty 

Please, could you be so kind as to help with some suggestions? I am starting to feel desperate. The attempt to protect the TV decoder was based on the following article:
 

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Placing-FortiGate-between-a-TV-service-provider-s/ta-p/433868

 

Maybe this article could inspire you to find the solution to my problem. Please, help.

Thank you very much.

 

 

Jean-Philippe_P
Staff & Editor
Staff & Editor
May 6, 2026

Hello FortiSpain,

 

I found this solution, can you tell us if it helps, please?

 

To address the issues you're experiencing with your FortiGate setup, let's break down the symptoms and potential solutions:

 

Symptom 1: IP Assignment Delay and STP

Issue:
Your MacBook Air is experiencing a delay in obtaining a normal IP address when connected to the network provided by one of the routers. This issue is resolved when STP (Spanning Tree Protocol) is disabled, but STP was previously enabled without issues.

 

Potential Causes and Solutions:

  1. STP Configuration:

    • Ensure that the STP settings on your FortiGate and any connected switches are correctly configured. Misconfigurations can cause network loops or delays in port forwarding.
    • If STP is necessary for your network topology, consider adjusting the STP priority settings to ensure that the correct device is the root bridge.
       
  2. VLAN Configuration:

    • Double-check the VLAN settings on your FortiGate and ensure that the VLAN is correctly configured to handle traffic from both routers.
    • Verify that the VLAN tagging is consistent across all devices in the network.
       
  3. DHCP Settings:

    • Ensure that the DHCP server settings on the FortiGate are correctly configured to provide IP addresses without delay.
    • Check for any IP address conflicts or lease time issues that might be causing the delay.
       

Symptom 2: ProtonVPN Connection Issues

Issue:
You are unable to connect to ProtonVPN, with errors indicating DNS problems or configuration issues.

 

Potential Causes and Solutions:

  1. DNS Configuration:

    • Verify that the DNS settings on your FortiGate are correctly configured. Ensure that the DNS servers are reachable and correctly resolving domain names.
    • Consider using public DNS servers like Google DNS (8.8.8.8, 8.8.4.4) or Cloudflare DNS (1.1.1.1) to see if the issue persists.
       
  2. Firewall Policies:

    • Check the firewall policies on your FortiGate to ensure that traffic to and from ProtonVPN servers is not being blocked.
    • Ensure that the necessary ports for VPN traffic are open and that there are no restrictions on VPN protocols.
       
  3. VPN Client Configuration:

    • Verify the configuration settings in the ProtonVPN client to ensure they match the requirements for your network.
    • Ensure that any security software on your device is not interfering with the VPN connection.
       

Follow-ups and Clarification Questions

  1. Network Topology:
    Can you provide more details about your network topology, including any additional switches or devices that might be affecting the network?

  2. Configuration Changes:
    Are there any other configuration changes you made around the time the issues started, aside from the multicast policies?

  3. Logs and Diagnostics:
    Have you checked the FortiGate logs for any errors or warnings that might provide more insight into the issues?

  4. Firmware Version:
    What firmware version is your FortiGate running? Ensuring that your device is up-to-date can sometimes resolve unexpected issues.
     

By addressing these areas, you should be able to identify and resolve the issues affecting your network. If the problems persist, consider reaching out to Fortinet support for further assistance.

Jean-Philippe - Fortinet Community Team
AEK
SuperUser
SuperUser
May 6, 2026

Hello FortiSpain

I find the issue relatively complex and needs local troubleshooting so I cannot deal with it by messages. I recommend to show it to a FGT admin and let him work on it directly.

AEK
FortiSpain
Explorer
May 9, 2026

Hi AEK and Jean-Philippe,

 

Thank you very much for your replies.

Answering to Jean-Phillipe: j
 

Potential Causes and Solutions:

  1. STP Configuration:

    • Ensure that the STP settings on your FortiGate and any connected switches are correctly configured. Misconfigurations can cause network loops or delays in port forwarding.

If STP is necessary for your network topology, consider adjusting the STP priority settings to ensure that the correct device is the root bridge.

There are no physical switches connected to the FortiGate. However, Lan 2 and Lan 3 are a configured Vlan switch in the Fortigate. The internet from the “guilty” router is provided through those two Lans. On the GUI, the only STP setting is a “on/off” button which is set to “on”. So I do not know how to “adjust STP priority settings” on the FortiGate. The other router has STP tuned off (like in the previous configuration).


VLAN Configuration:

  • Double-check the VLAN settings on your FortiGate and ensure that the VLAN is correctly configured to handle traffic from both routers.
  • Verify that the VLAN tagging is consistent across all devices in the network.


I have no idea how to do that.

DHCP Settings:

  • Ensure that the DHCP server settings on the FortiGate are correctly configured to provide IP addresses without delay.
  • Check for any IP address conflicts or lease time issues that might be causing the delay.

Yes; maybe the problem comes from the lease time. In order to avoid them, I have reinstalled the OS on the Macbook Air… But problems are still the same.

On the DHCP Monitor window of the GUI, the following message appears: “Failed to load Topology Report results”. These are the lines (I have deleted mac addresses and other devices):

 


I do not know why my Mac shows two different mac addresses…

 

Symptom 2: ProtonVPN Connection Issues

Issue:
You are unable to connect to ProtonVPN, with errors indicating DNS problems or configuration issues.

 

Potential Causes and Solutions:

  1. DNS Configuration:

    • Verify that the DNS settings on your FortiGate are correctly configured. Ensure that the DNS servers are reachable and correctly resolving domain names.
    • Consider using public DNS servers like Google DNS (8.8.8.8, 8.8.4.4) or Cloudflare DNS (1.1.1.1) to see if the issue persists.

As far as I can see,  when I go to Network » DNS, the DNS settings seem to be correctly configured (comparing to previous configuration)  The DNS servers are the FortiGuard ones: 96.45…. and 96.45…. Both shows green ms values. 

When I go to Network » Interfaces » Vlan Switch, I can see: DHCP Servers:
Status: enabled
Addressing mode: Manual
Address range (seems to be OK with my Macbook IP)
Netmask:….
Default gateway: Same as Interface IP
DNS Server: Specify 

  • DNS server 1: 8.8.8.8
  • DNS server 2: 9.9.9.9

Lease Time: ON. 604800 seconds
FortiClient On-Net Status: ON. Default

Advanced

Mode: Server

Type: Regular
NTP server: Specify (but the space is empty)
Wireless Controllers: Specify (but the space is empty)… Note: I do not use any wireless system (no bluetooth, no WiFi).

Time zone: Same as System
Next bootstrap server: 0.0.0,0

TFTP server(s): empty

Additional DHCP Options: empty
IP Address Assignment Rules: implicit / Unknown MAC Addresses / Assign IP

Network:
Device detection: ON
Automatically authorize devices: OFF 
STP: ON
Security Mode: OFF

SPAN (Port Mirroring): OFF

Traffic shaping 
Outbound Shaping Profile: OFF
Outbound Shaping: OFF

Miscellaneous:

STATUS: Enabled.

I hope this will help you… And so will help me.
 

Firewall Policies:

  • Check the firewall policies on your FortiGate to ensure that traffic to and from ProtonVPN servers is not being blocked.
  • Ensure that the necessary ports for VPN traffic are open and that there are no restrictions on VPN protocols.

I have a policy which blocks malicious lists. Just in case, I have disabled it but the issue persists. Regarding ports, all of them are closed as I do not use FortiGate VPN. I use Proton VPN using the app. I have never had issues until now. 

 

VPN Client Configuration:

  • Verify the configuration settings in the ProtonVPN client to ensure they match the requirements for your network.
  • Ensure that any security software on your device is not interfering with the VPN connection.

I can not enter in the app, so I can not reach the configuration settings in the Proton VPN client. There is no security software on my Macbook Air. But it is updated as well as all the apps.

Note: Now Proton VPN app only mentions that the password is not correct. It never mentioned again the DNS issues or that the Proton Servers are not reachable.
 

Follow-ups and Clarification Questions

  1. Network Topology:
    Can you provide more details about your network topology, including any additional switches or devices that might be affecting the network?

Here you go:

Router 1 (which is showing problems) is connected to Lan1 which is configured as WAN2. Router 2 (Which only shows problems with Proton VPN) is connected to WAN. SD-WAN = Lan1 + WAN.
Lan 2 + Lan 3 = Vlan switch called “lan”, These ones are providing the internet from the Router 1.

Lan 4 (or “A”) is providing internet from Router 2.

No physical switcher and everything is connected by cables (Ethernet).
 

  1. Configuration Changes:
    Are there any other configuration changes you made around the time the issues started, aside from the multicast policies?
     

Configuring the Multicast policies, I had to use Lan 1 (WAN2) as you can see on the provided article. But I could not use WAN2 only as it is part of SD-WAN, so I used SD-WAN… Maybe the mistake comes from this.

  1. Logs and Diagnostics:
    Have you checked the FortiGate logs for any errors or warnings that might provide more insight into the issues?

The following message appears a lot of times: “SD-WAN health-check member changed state”. All warnings in Log & Report > system events are blue or green.

Nothing relevant in Security events
 

  • Firmware Version:
  • What firmware version is your FortiGate running? Ensuring that your device is up-to-date can sometimes resolve unexpected issues: 7.6.6 build3652. Up to date.

I hope all this information can help you to help me.

​​​​​​​Thank you very much to all.
​​​​​​​ 

​​​​​​​

Jean-Philippe_P
Staff & Editor
Staff & Editor
May 11, 2026

Hello again FortiSpain,

 

I found that answer, I hope it helps:

 

To address the issues you're experiencing with your FortiGate setup, let's break down the potential causes and solutions based on your detailed description:

 

1. STP Configuration

  • Current Setup: You mentioned that STP is enabled on the FortiGate VLAN switch, but the other router has STP turned off.
  • Solution: Since there are no physical switches, the STP configuration on the FortiGate should suffice. However, if STP is causing delays, consider temporarily disabling it to see if the issue resolves. If STP is necessary, ensure that the FortiGate is correctly set as the root bridge by adjusting the priority settings, if available.
     

2. VLAN Configuration

  • Current Setup: You are unsure about VLAN settings.
  • Solution: Verify that the VLAN configuration on the FortiGate is consistent with your network design. Ensure that VLAN tagging is correctly set up and that the VLAN switch is handling traffic from both routers as intended. You may need to consult the FortiGate documentation or support for detailed VLAN configuration steps.
     

3. DHCP Settings

  • Current Setup: You suspect lease time issues and have reinstalled the OS on your MacBook Air.
  • Solution: Check the DHCP lease time settings on the FortiGate. A lease time of 604800 seconds (7 days) is standard, but you can try reducing it to see if it affects the issue. Ensure there are no IP conflicts by checking the DHCP monitor for duplicate IP addresses.
     

4. ProtonVPN Connection Issues

  • DNS Configuration:

    • Current Setup: Using FortiGuard DNS servers and public DNS servers (8.8.8.8 and 9.9.9.9).
    • Solution: Ensure that DNS settings are correctly applied across all interfaces. You might want to temporarily switch to using only public DNS servers to see if it resolves the issue.
  • Firewall Policies:

    • Current Setup: A policy blocking malicious lists was disabled, but the issue persists.
    • Solution: Ensure that no firewall policies are inadvertently blocking VPN traffic. Check that necessary ports for ProtonVPN are open.
  • VPN Client Configuration:

    • Current Setup: Unable to access ProtonVPN client settings.
    • Solution: Reinstall the ProtonVPN client and ensure no security software is interfering. If the password issue persists, verify credentials and consider resetting the password.
       

5. Network Topology and Configuration Changes

  • Current Setup: Router 1 is connected to LAN1 (WAN2), and Router 2 is connected to WAN. LAN2 and LAN3 form a VLAN switch.
  • Solution: Review the SD-WAN configuration, especially if changes were made during multicast policy setup. Ensure that SD-WAN rules are correctly routing traffic between the routers.
     

6. Logs and Diagnostics

  • Current Setup: Frequent "sd-wan health-check member changed state" messages.
  • Solution: Investigate the SD-WAN health-check configuration. Frequent state changes might indicate connectivity issues or misconfigurations.
     

7. Firmware Version

  • Current Setup: Running firmware version 7.6.6 build 3652.
  • Solution: Ensure that this is the latest stable release for your device. If not, consider upgrading to the latest version.
     

Follow-ups and Clarification Questions

  • Network Topology: Are there any additional devices or configurations not mentioned that might affect the network?
  • Configuration Changes: Were there any other changes made around the time the issues started, aside from the multicast policies?
  • Logs and Diagnostics: Have you checked for any specific errors or warnings in the FortiGate logs that might provide more insight into the issues?
     

If these steps do not resolve the issues, consider reaching out to Fortinet support for further assistance.

Jean-Philippe - Fortinet Community Team
FortiSpain
Explorer
May 11, 2026

Thank you very much for your time and for your dedication. I have notified Fortinet Support. 

All the best to all!