Description | This article explains the workaround to process if the DHCP is enabled on both FortiGates in the VRRP cluster. |
Scope | FortiGate. |
Solution |
When FortiGate is on a VRRP cluster with another FortiGate (or other device that supports VRRP) it means the DHCP is enabled on both devices. During the event of VRRP failover, there is a chance that the standby VRRP device will lease an overlapping IPv4 address when the standby becomes active. The ideal setup in a VRRP environment is to have a separate and dedicated DHCP server as layer2 devices can detect multiple DHCP servers in the same network since the DHCP on both devices is independent.
If there is no dedicated DHCP server, it is possible to split the DHCP server pool on both FortiGates to avoid leasing overlapping IPv4 addresses in the event of VRRP failover.
From GUI:
FortiGate-A # show system dhcp server
|
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.