Hello all.
If you are using a Fortigate with the Belgian Cable ISP Telenet, you should know that there is a known incompatibility between Fortigates and the new Telenet DOCSIS 3.1 E-ROUTER. This is the kind of router that they install for all new clients. For now, it is possible to request Telenet to install a DOCSIS 3.0 modem and that solves the issue, but going forward this could become a big problem, especially if they require all their clients to switch to DOCSIS3.1.
The problem seems to be that Fortigates don't support Unicast DHCP.
As far as I can tell the incompatibility is known to Telenet, but I don't know if Fortinet knows or not. I have opened a TAC case to find out.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
I saw similar issues with Netgear modems used by Comcast in the States. Wonder if they use the same hardware.
Can you explain unicast DHCP? The whole purpose of DHCP is the client has no "address" so how is unicast used here? Outside of a DHCP-relay concept, DHCP is broadcasted
Ken Felix
PCNSE
NSE
StrongSwan
From what I understand, "Unicast DHCP" is a misnomer.
Unicast refers to the Broadcast flag set in the Bootp flags. The Fortigate sets it to "Broadcast", whereas regular Windows/MacOS clients set it to "Unicast".
Interesting i would have to capture a DHCP datagram, but broadcast and unicast just determines the action of the DHCP-offer as 0.0.0.0 or x.x.x.x in the offer from my understanding.
In the above you would need to look at the offer and witness is being set imho. I would use a dhcp-tool to test the above with the ISP and see what's happening or grab the difference 2 or more different devices for comparison.
Ken Felix
PCNSE
NSE
StrongSwan
Hi,
I'm experiencing exactly the same problem. Did you already found a fix for this or did you just change your modem with a DOCSIS 3.0 one?
I just swapped my DOCSIS 3.0 for a 3.1 one, but didn't do enough research to find this before hand. Can I possible fix this with the 3.1 modem?
Hi,
Does anyone know if this issue has been resolved with a fortinet update?
thanks
I can tell you that in the mean time this bug has been fixed. I'm using a DOCSIS 3.1 E-ROUTER from Telenet with a Fortigate firewall myself and the bridging functionality works without flaws.
That's great! Which version are you on?
Kind regards,
Any idea how I can find on which version I am?
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1733 | |
1106 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.