FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
epinheiro
Staff
Staff
Article Id 280863
Description

This article describes a workaround where the DHCP client can get an IP address from the DHCP server (upstream device) when the FortiGate is in policy-based mode, and a software switch is being used to aggregate interfaces to interconnect the client and the DHCP server.

 

Topology:

Laptop (DHCP Client) -> Switch -> FortiGate Software Switch interfaces -> Router (DHCP Server)

 

Topology.jpg

 

When configuring the software switch interface, there are two intra-switch policy options:

  1. Implicit: Basically, it will allow connectivity between the interface members without any additional configurations, such as firewall policy, SSL Inspection profile, NAT, etc.
  2. Explicit: Connectivity between the interfaces is denied by default, and according to your setup, you need to configure firewall policy, SSL Inspection profile, NAT, etc.

 

If the implicit option is chosen, everything will work fine. Otherwise, stumble on the following issue:

 

Explicit.jpg

 

  • The DHCP client will 'Discover' the DHCP server.
  • The DHCP server will 'Offer' an IP address.
  • The DHCP client will 'Request' the offered IP, but will not have 'ACK' from the DHCP server.

 No_ACK.jpg

 

Scope

FortiGate v5.6 and above.

Solution

The current workaround is choosing the implicit intra-switch policy, instead of the explicit policy.

 

When the software switch interface is already created, the intra-policy mode cannot be changed. So, it is necessary to remove all the references from the software switch interface, delete it, and then set the option 'Implicit' while re-creating it.

 

  •  Checking the references before trying to delete the software switch interface:

 

Reference.jpg

 

  • Creating a new software switch interface:

 

Implicit.jpg

 

  •  After creating the software switch interface using implicit intra-policy mode, it is time to test the DHCP Server:

ACK.jpg

 

 

 

 

 

Comments
mauromarme
Staff
Staff

Very Useful information! Great job. 

Contributors