Solved

DHCP negotiation failure

Posted on 2006-06-29
8
1,132 Views
Last Modified: 2013-11-30
I'm having a problem with intermittent connectivity to my ISP.  Every few minutes, hours, or days (it varies) my internet connectivity will slow to a crawl and eventually fail altogether.  No traffic in or out.  The solution is to reboot the firewall and then service will return until the next incident.  The components involved are a Watchguard SOHO 6 firewall to a Motorola Surfboard 5120 cable modem to the ISP, Suscom.   The Soho is at the latest firmware revision.
The Soho's log file reveals that DHCP negotiation may be part of the problem.  I'm seeing a recurrence of the error message "DHCP response has incorrect ID" timed coincident to the slowdown of internet connectivity.  Otherwise the log file looks normal.   In an attempt to resolve the issue I have installed a hub between the Soho and the cable modem but that has not helped.  I've also tried stepping down the Soho's WAN link speed to 10 half which has not improved things.   Suscom support is unable to find any problem with their service.  Suscom and Watchguard both claim their equipment to be RFC compliant.   My options, as I see them are to swap the Soho or to swap ISPs or to pull more of my hair out (which I really can't afford.)

So, my collegues, the question is:  What tools or techniques might I employ to further diagnose the source of this apparant DHCP problem?
0
Comment
Question by:pnkljohnson2
8 Comments
 
LVL 2

Accepted Solution

by:
skags442 earned 125 total points
Comment Utility
for testing's sake, take the soho out of the picture and see how you pc deals with the connection, if all is good with the pc, then you can safly assum its the soho, and if thats the case, your isp might have a certin thing that may need to be set, like the mtu settings. but i would first make sure its the soho first.
0
 
LVL 2

Expert Comment

by:skags442
Comment Utility
another thing you could try is dissconnect your cable modem from everything including the coax, and let it sit for about 5 min, and try it again
0
 
LVL 30

Expert Comment

by:ded9
Comment Utility
http://www.gfi.com/

download tools from the above site detects any kind of network problems

Its the no1 software in the market

Reps
0
Better Security Awareness With Threat Intelligence

See how one of the leading financial services organizations uses Recorded Future as part of a holistic threat intelligence program to promote security awareness and proactively and efficiently identify threats.

 
LVL 2

Assisted Solution

by:wtbservices
wtbservices earned 125 total points
Comment Utility
You said that restarting the router clears the problem so that is where I would start looking. Since you have a hub in the line between the modem and the router I would connect a computer  into the hub and run Ethereal to capture the traffic. Then initiate a DHCP renew on the router and see if you can observe the 4 DHCP packets back and forth (discover, offer, request, acknowledge). Bear in mind that this would likely only be usefull once the connection is down although it could be informative to see what was happenning when it was running smoothly. Also, be sure that the computer you have connected to the hub has a static IP address assigned since you don't want it sending a DHCP request to the modem.
0
 
LVL 2

Expert Comment

by:monkeyjr
Comment Utility
Please check the DHCP request is from which device by its MAC address. Also check the firewall setting, it seems the DHCP service become DoS attack. Or you can try to drop those packets when these packets come to the firewall from same machine in a short period (ping request, DHCP request, etc).
0
 
LVL 1

Author Comment

by:pnkljohnson2
Comment Utility
Sorry for not getting back.  I haven't yet returned to the customer's site.
0

Featured Post

Give your grad a cloud of their own!

With up to 8TB of storage, give your favorite graduate their own personal cloud to centralize all their photos, videos and music in one safe place. They can save, sync and share all their stuff, and automatic photo backup helps free up space on their smartphone and tablet.

Join & Write a Comment

Even if you have implemented a Mobile Device Management solution company wide, it is a good idea to make sure you are taking into account all of the major risks to your electronic protected health information (ePHI).
Join Greg Farro and Ethan Banks from Packet Pushers (http://packetpushers.net/podcast/podcasts/pq-show-93-smart-network-monitoring-paessler-sponsored/) and Greg Ross from Paessler (https://www.paessler.com/prtg) for a discussion about smart network …
Here's a very brief overview of the methods PRTG Network Monitor (https://www.paessler.com/prtg) offers for monitoring bandwidth, to help you decide which methods you´d like to investigate in more detail.  The methods are covered in more detail in o…
In this tutorial you'll learn about bandwidth monitoring with flows and packet sniffing with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're interested in additional methods for monitoring bandwidt…

772 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

12 Experts available now in Live!

Get 1:1 Help Now