Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Not applicable

DHCP relay is not working

We have two FGt 3000 in a cluster. We have a DHCP server connected on our management VLAN which serves a lot of the customers connected on individual VLANs. The DHCP requests are relayed to the DHCP server. Shortly after update to MR5 the DHCP relay function stopped working. I can see the DHCP request on the interface where the requesting device is connected, but nothing on the interface where the DHCP server is connected. Is ther anyone who ca give me a hint on what may be wrong? Thanks Magne
16 REPLIES 16
Yngve0
New Contributor II

Hei, I had the same issue here om our FG50A after upgrading to MR5, so I had to downgrade all 17 locations to MR3 again. I made a support issue on that in may/june (build 547) and Fortinet claimed few days ago that this was solved in 559. This time I tried more carefully with one location (the closest one) and the problem is still there. Support is informed, but it would be nice if you posted it as well. Yngve
Not applicable

Thanks We have 559 on our boxes. Support is informed. Magne
rwpatterson
Valued Contributor III

Build 564 is out. Give that a shot.

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
Yngve0
New Contributor II

Seems like not :( Yngve
Carl_Wallmark

Im using build 564 and with DHCP Relay enabled on 120 VLANS - and it works perfectly !

FCNSA, FCNSP
---
FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30B
FortiAnalyzer 100B, 100C
FortiMail 100,100C
FortiManager VM
FortiAuthenticator VM
FortiToken
FortiAP 220B/221B, 11C

FCNSA, FCNSP---FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30BFortiAnalyzer 100B, 100CFortiMail 100,100CFortiManager VMFortiAuthenticator VMFortiTokenFortiAP 220B/221B, 11C
Yngve0

I dont know what Magnnyb' s scenario is, but mine issue was DHCP-relay through VPN in IPSEC interface mode. It was working perfect in MR3, but not with the same configuration in MR5. I got some answer from FG-support that I had to define a new rule: Local-interface (All) -> VPN-interface (All) for DHCP-server. But on a earlier issue, I was told not to use " ALL" as host on VPN-rules, since that will mess up the box. Based on that experience, I asked for some clarification. Yngve
abelio

I dont know what Magnnyb' s scenario is, but mine issue was DHCP-relay through VPN in IPSEC interface mode.
Interesting note about this in IPSec VPN User Guide (FortiOS 3.0) (pag 57)
 Note: FortiGate units fully support RFC 3456, Dynamic Host Configuration Protocol
 (DHCPv4) Configuration of IPsec Tunnel Mode. The FortiGate DHCP over IPSec feature
 can be enabled to allocate VIP addresses to FortiClient dialup clients using a FortiGate
 DHCP server if a policy-based VPN is configured. DHCP over IPSec is not compatible with
 FortiGate route-based VPNs.
 

regards




/ Abel

regards / Abel
Yngve0
New Contributor II

Upgrading Firmware is an hazard-game;
DHCP over IPSec is not compatible with FortiGate route-based VPNs.
From Configuration of DHCP relay through a Fortigate-to-Fortigate IPSec VPN
Configuration example of regular DHCP relay through a Fortigate-to-Fortigate IPSec VPN Please note that although a DHCP request is being relayed through an IPSec tunnel, this is not a “DHCP-over-IPsec” feature configuration. In a typcial “DHCP-over-IPsec” feature configuration, the DHCP broadcast request is sent from a client (ex: FortiClient), through an IPSec tunnel, and relayed from the remote-end Fortigate unit (FGT60 in the example below) to an internal DHCP server.
When a function that worked perfect earlier change to worse, Fortinet prefer to define the previous functionalty as a bug. . . . . Y
Not applicable

I am using regular DHCP relaying (no IPsec)
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors