FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
jfelix09
Staff
Staff
Article Id 405941
Description This article describes an issue when IPAM features are enabled on FortiGate system interfaces.
Scope FortiGate v7.4.8.
Solution

When configuring the IPAM feature on FortiGate system interfaces, the DHCP server settings may not automatically be assigned based on the IPAM configuration for the Security Fabric root FortiGate. The DHCP server address range may remain in a 'not allocated' state, and the netmask may display as '0.0.0.0/0'. If the DHCP server status is enabled manually, an error message stating 'empty values are not allowed' will be displayed.

 

ipam-issue.png

 

The IPAM daemon debugs will mention that it fails to create a DHCP server for the configured IPAM interface:

 

diagnose debug application ipamd -1

diagnose debug enable

 

Review the debug output for errors such as:

 

<2247> 08 ipam_set_interface_ip()-251: Setting interface port4 to IP 172.31.0.254 netmask 255.255.255.0
<2247> 08 ipam_prepare_initial_intf_dhcp()-539: Created DHCP server for interface port4
<2247> 02 ipam_dhcp_set_table_to_one_range()-717: Could not clear ip-range table for dhcp server
<2247> 02 ipam_set_interface_ip()-304: Failed to set interface DHCP for port4
<2247> 02 ipam_intf_subnet_request_rh()-204: Failed to apply interface settings, forcing an update for port4
<2247> 04 ipam_send_all_needed()-328

 

This issue is resolved in FortiOS version 7.6.0 and above (known issue ID 1037480). 

 

Related documents:

Configure IPAM locally on the FortiGate