Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

DHCP Relay over Routing-Based IPsec in SFOS 18.0.1 not working

On an XG 135 with SFOS 18.0.1 the DHCP relay over a Routing-Based IPsec tunnel is not working.

System traffic over the IPsec is working. Firewall authentication on the Active Directory servers behind the same IPsec tunnel is working.
Those same Active Directory servers are also the DHCP servers.

DHCP packets are received by the LAN port (can be seen both on the packet catpure and the TCPDUMP) but the traffic is not routed through the IPsec tunnel.
Packet capture reports "ACL 

Firewall rule allowing any/any to DHCP servers is in place.

DHCP service of the firewall is working and firewall is providing DHCP addresses.



This thread was automatically locked due to age.
Parents
  • DHCP Relay should not need a Firewall rule. 

    I remember, that DHCP Relay is not supported for VTI, but i am not 100% sure. Read something about this. 

    Do you have multiple DHCP Relays configured on this Appliance? If you delete all except one, is it working? 

    Did you tick the option "relay on IPsec"? Please disable this option and try again. 

Reply
  • DHCP Relay should not need a Firewall rule. 

    I remember, that DHCP Relay is not supported for VTI, but i am not 100% sure. Read something about this. 

    Do you have multiple DHCP Relays configured on this Appliance? If you delete all except one, is it working? 

    Did you tick the option "relay on IPsec"? Please disable this option and try again. 

Children