Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

DHCP relay issue after upgrade to SFOS 17.0.1 MR-1

We are running our XG 210 on version 16 for a few months now. Our network configuration has 3 VLAN's. DHCP for couple of the VLANS is setup as relay to Windows Domain controller and for another VLAN was setup as XG Firewall. Everything was working like a charm till the firmware upgrade.

Yesterday I upgraded to the firmware to v17 and then MR-1. Since the upgrade the devices on DCHP relay VLAN's  are not allocated IP address. I see a DHCP lease is created on Windows domain controller but IP is not allocated to the device.

I see posts where others had similar issues with previous versions, I am not exactly sure if any of those are applicable to my scenario. Any help in resolving is much appreciated.

- Kamal

 

Update 01

As mentioned in other posts with similar issues, I ran the following command and can see the entry for a MAC address matchine one of the devices.

console> drop-packet-capture

Date=2017-11-28 Time=10:16:08 log_id=0103021 log_type=Firewall log_component=Local_ACLs log_subtype=Denied log_status=N/A log_priority=Alert duration=N/A in_dev=Port1.300 out_dev= inzone_id=10 outzone_id=4 source_mac=38:a4:ed:67:41:25 dest_mac=ff:ff:ff:ff:ff:ff l3_protocol=IP source_ip=0.0.0.0 dest_ip=255.255.255.255 l4_protocol=UDP source_port=68 dest_port=67 fw_rule_id=0 policytype=0 live_userid=0 userid=0 user_gp=0 ips_id=0 sslvpn_id=0 web_filter_id=0 hotspot_id=0 hotspotuser_id=0 hb_src=0 hb_dst=0 dnat_done=0 proxy_flags=0 icap_id=0 app_filter_id=0 app_category_id=0 app_id=0 category_id=0 bandwidth_id=0 up_classid=0 dn_classid=0 source_nat_id=0 cluster_node=0 inmark=0x0 nfqueue=0 scanflags=0 gateway_offset=0 max_session_bytes=0 drop_fix=0 ctflags=0 connid=863434432 masterid=0 status=256 state=0 sent_pkts=N/A recv_pkts=N/A sent_bytes=N/A recv_bytes=N/A tran_src_ip=N/A tran_src_port=N/A tran_dst_ip=N/A tran_dst_port=N/A



This thread was automatically locked due to age.
Parents
  • Hi,

    have you figured out a solution for this problem yet?

    I've got pretty much the same issue here, except that only the clients reside in a VLAN whereas the DHCP server is in the untagged LAN. There's one relay for the untagged LAN port pointing to one server (which presumably works, although I cannot verify it's routed through the relay, as the DHCP server is reachable by itself) and another one for the VLAN port, which also forwards to another server in the LAN zone.

    Looking at the logs of the second server, responsible for serving clients from the VLAN only, the DISCOVER is forwarded and an OFFER is generated and sent back to the relay. However, neither an ACK or a NAK message is to be found afterwards. Only if I run another DHCP server directly on the VLAN the NAKs are forwarded, as the clients already get an IP from another server.

    Sincerely,

    Jonas

  • Hi Jonas,

    Not much luck with the issue yet. I have raised a ticket with Sophos support to help out with troubleshooting.

     

    -Kamal

  • Hi all, I also have this. Confirmed by support as know issue (BUG ID NC-20755). The WA provided was to reconfigure the DHCP Relay option on every Vlan and restart XG. I am waiting to check if the WA works. I think it does not make any sense, to announce the MR1 knowing in advance this kind of problems.
  • We gave up perhaps it was too early to try it. Got our sophos partner to rollback firmware to SFOS 16.05.8 MR-8 and everything works like a charm again :(

    - Kamal

  • Thanks Peter, unfortunately as our network was seriously crippled for a week we decided to rollback to 16 MR-8. Will take a note of the workaround if we face this issue if we decide to upgrade again.

     

    Regards

    Kamal 

Reply Children
No Data