Hi there, lost our WAN connection due to a severed fiber line. Strangely, this has impacted our 200E's ability to issue DHCP requests. As lease's expire and drop off, users aren't able to get a new one. Is this a known issue. Hoping that when WAN connection gets back up, fortigate will return to normal. Right now it seems confused. Even when trying to look at DHCP connections through GUI is usually times out.
Also, currently running OS 6.2.3. Wondering what the most stable release is that we should look at updating to. Hoping this might help address this issue. We definitely don't have another rogue DHCP server on our network.
Any help would be appreciated. Thank you!!
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
For what it's worth, fiber line was just repaired so I now how internet again (WAN connection) and fortigate is now handing out dhcp requests again. Doesn't make any sense to me but it's working. Would like to understand why it's happening though....
Hi there,
According to your description, the Fortigate might be acting as a DHCP relay agent for clients, that are getting IP addresses from a DHCP server that is reachable via IPSec tunnel.
And since the wan connections was down(and so IPSec), the DHCP server might not be reachable.
Anyway, since the issue is not in place, it would be hard to understand what was happening there.
Ahmad
Created on 05-10-2022 05:43 AM Edited on 05-10-2022 05:44 AM
Thanks for the input. I checked all of our network interfaces both physical and vlans and all DHCP was set as servers, not relays. We do have a VPN Ipsec tunnel for remote users but this has a defined range of addresses that it allocates. Any idea where I could look to check this behaviour. Note, I've also seen other users mention this in other threads although no one has really understood why. Thanks.
Hi,
Next time the issue happens, collect a debug and a sniffer. You may create a ticket and attach the info for investigation.
https://community.fortinet.com/t5/FortiGate/Technical-Tip-Diagnosing-DHCP-on-a-FortiGate/ta-p/192960
diag sniffer packet any 'port 67' 6 0 l
Regards,
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1709 | |
1093 | |
752 | |
446 | |
231 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.