Created on 06-29-2022 11:29 PM Edited on 11-12-2024 10:38 PM By Anthony_E
Description | This article helps to troubleshoot the FortiGate DHCP when it is receiving error DHCP DECLINE on debug. |
Scope |
FortiGate is the DHCP server and the client is not getting any DHCP IP.
When running the debug '# diag debug application dhcpc -1', the error DHCP DECLINE is visible.
Sample 1:
2022-06-08 18:28:52 [note]DHCPDECLINE on 172.22.1.2 from 98:fa:9b:89:da:d6 via port4(ethernet)
Sample 2:
Receive packet:
|
Solution |
config firewall ippool
By default, the IPpool is configured to have the 'arp reply' enabled, this will cause the FortiGate itself to respond to the DHCP probe.
To be sure, it is possible to use the sniffer command to check the ARP:
diag sniff pac <port> "arp" 4
Remove the IPpool or change the DHCP IP to another range.
|
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.