Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
jdsauer77
New Contributor

VLAN Client not getting DHCP Address

Hello All,

I have a Fortigate 60F connected to a Ubiquiti switch, using Ubiquiti Access Points. On the Ubiquiti, I have configured my main network (works without issue), as well as 2 VLANs. I am attempting to connect to one of those VLANs and it seems I can connect to the wireless part of it, but I can't get a DHCP address from either the Fortigate or from my Windows DHCP server when using the "Relay" mode on the Fortigate to assign the address.

There's no option on the Ubiquiti Cloud Controller to define a DHCP Server, so I am assuming that it just lets the client connect to another device that's on the same VLAN to request the DHCP response. However, that does not seem to be happening.

Until I can afford to go all Fortinet (hopefully in a few months) with a Fortigate, Fortiswitches, and FortiAPs, this is the configuration I have.
Has anyone else run into this? The network I am trying to connect on is a VLAN (guest network, testing so when people come over they are not on my main home domain). From what I can see in the logs, the request is sent, but the Fortigate doesn't seem to be sending that request anywhere, even if it's on the device itself.

5 REPLIES 5
AEK
SuperUser
SuperUser

Hi @jdsauer77 

First thing I'd do is set a static IP for my client in the right subnet and try ping my gateway.

If it works I'm in the right VLAN, otherwise something wrong somewhere at L2 level.

AEK
AEK
funkylicious

that and i would also check if there is a firewall policy in place to allow DHCP traffic towards the Win Server with DHCP if they are in different VLANs since you configured with Relay, otherwise if they are in the same VLAN no need for it and the broadcast should reach it, in which case tshoot the server.

as AEK mentioned, try setting a static IP and check reachability then change focus on fw rules if any required.

"jack of all trades, master of none"
"jack of all trades, master of none"
hbac
Staff
Staff

Hi @jdsauer77,

 

Can you make sure that the user is connected to the correct VLAN? You can also run DHCP debugs to see if FortiGate is receiving DHCP requests or not. https://community.fortinet.com/t5/FortiGate/Technical-Tip-Diagnosing-DHCP-on-a-FortiGate/ta-p/192960

 

Regards, 

cwillard
New Contributor

I'm having the exact same issue at a client. It seems the Cloud Key does not have the ability to work in this fashion. I have not been able to find any other solutions/work arounds.

MLaForge
New Contributor

I am also running into this issue.  The way around it I have found is for the AP Native VLAN create a scope on the switch directly and turn it off for that VLAN on the Fortinet.  In some of our smaller clients that have no DHCP servers but we want to have multiple VLANs for several reasons but do not want any type of traffic isolation, I created the scopes on the switches.  We then have an isolated vlan to the fortinet that internet bound traffic goes through.  This works flawlessly with the Ubiquiti devices.

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors