FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
mle2802
Staff
Staff
Article Id 291503
Description

This article describes reasons why the client receives a different DHCP scope.

Scope

FortiGate and Windows.

Solution

On FortiGate, there are 2 different DHCP scopes which are port7 and vlan 70.


DHCP scope.PNG

 

The client host is intended to get the IP from the VLAN 70 DHCP scope, but here it is receiving the 10.10.10.0/24 range instead.

 

wrong ip.PNG

 

This is because traffic is not being tagged with the correct VLAN ID. In this example, it is possible to tag the VLAN ID on a Window NIC using the following steps:

  1. Open Device manager on the Window machine.
  2. In Device Manager, open Network adapters.
  3. Right-click on the NIC and choose Properties.
  4. Select the Advanced tab.
  5. Scroll down to VLAN ID.
  6. Set the ID that is desired for the NIC to have and select OK.

vlan tag.PNG

 

After that, renew DHCP and confirm if it is getting the correct IP now.


right IP.PNG

 

Note:

For an Intel NIC, it may be necessary to install Intel Advanced Network Services. See:

Intel® Advanced Network Services for more information.

 

Here is a related article that provides an example packet capture of DHCP Messages with a VLAN tag: 

Troubleshooting Tip: Check DHCP Messages with VLAN Tag using Wireshark Packet Capture