This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

DHCP Relay doesn't seem to work

Hi All,

Running an SG105 (SFOS 16.05.1 MR-1) and am having major issues getting the DHCP relay working.

I've got our VoIP network on eth0.900 (tagged VLAN 900) and everything works on a static IP address but the DHCP relay just isn't working. I've set it under Networks > DHCP > DHCP Relays as:

Name: VoIP_Relay
Interface: #eth0.900
DHCP Server IP: 10.0.48.252 (our DHCP IP on eth0 untagged)
IP Family: IPv4

Now nothing seems to be getting an IP from the 10.0.50.0/27 scope I've defined on our DHCP server (#eth0.900 is 10.0.50.1/27 on the Sophos). I can see this on the console if I run a firewall log on the console:

Date=2017-02-22 Time=10:58:38 log_id=0103021 log_type=Firewall log_component=Local_ACLs log_subtype=Denied log_status=N/A log_priority=Alert duration=N/A in_dev=eth0.900 out_dev= inzone_id=1 outzone_id=4 source_mac=38:bb:3c:be:e6:67 dest_mac=ff:ff:ff:ff:ff:ff l3_protocol=IP source_ip=0.0.0.0 dest_ip=255.255.255.255 l4_protocol=UDP source_port=68 dest_port=67 fw_rule_id=0 policytype=0 live_userid=0 userid=0 user_gp=0 ips_id=0 sslvpn_id=0 web_filter_id=0 hotspot_id=0 hotspotuser_id=0 hb_src=0 hb_dst=0 dnat_done=0 proxy_flags=0 icap_id=0 app_filter_id=0 app_category_id=0 app_id=0 category_id=0 bandwidth_id=0 up_classid=0 dn_classid=0 source_nat_id=0 cluster_node=0 inmark=0x0 nfqueue=0 scanflags=0 gateway_offset=0 max_session_bytes=0 drop_fix=0 ctflags=0 connid=3851835264 masterid=0 status=256 state=0 sent_pkts=N/A recv_pkts=N/A sent_bytes=N/A recv_bytes=N/A tran_src_ip=N/A tran_src_port=N/A tran_dst_ip=N/A tran_dst_port=N/A

Any ideas? It looks to me like the Sophos is blocking the broadcasts.



This thread was automatically locked due to age.
  • Hi,

    after setting up several branches with XGs and DHCP-Relay it seems to me that this is a self-regulating error.

    It took an estimated time between 30 minutes to two hours looking at port 67/68 regarded as "appliance access" and then being dropped (firewall log viewer).

    Meanwhile I can tell my customer to just be patient and it suddenly begins to turn green on ports 67/68 and fetching IP-Adresses.

    Good Luck

    Marc

     

    P.S. I enabled "Relay through IPSec" on all branches, dont' know if that matters.