Solved

Unable to get DHCP lease

Posted on 2010-08-23
11
967 Views
Last Modified: 2012-05-10
Hello,

We are having an issue with DHCP leases on our network.  Up until this point we only used static addressing.  At this time we need to be able to pull dynamic lease from one of our DCs.  In this instance our LAN_Client and LAN_DC just are not playing nice.  If you static the client devices IP they are able to communication with everything on the network.

How things move:  Client>DHCP Request>Switch>Firewall>Switch>Server

Our firewall policy is wide open at this time for traffic between the two VLANs.  The switch that is passing data is a PowerConnect 5424.

Detailed movement:  Client>DHCP Request>Switch>VLAN 15>Firewall>VLAN 10>Switch>DHCP response>Client

If we take a client device and connect it directly to VLAN 10 it is able to pull a dynamic address.  

Any thoughts as to what would be causing this?
0
Comment
Question by:jjl505
11 Comments
 
LVL 6

Expert Comment

by:Galtar99
ID: 33506492
Do you have IP helper (assuming you're running cisco switches) or similar statement on your client VLAN's to redirect the DHCP broadcasts to your DHCP server(s)?
http://www.cisco.com/en/US/docs/ios/12_1/iproute/command/reference/1rdipadr.html#wp1018606
0
 

Author Comment

by:jjl505
ID: 33506574
We are running Dell PowerConnect...
0
 
LVL 4

Expert Comment

by:bhartwell
ID: 33506855
Can your router be configured to allow BOOTP relay? Did you try setting up a dhcp relay agent on the VLAN 15 side of your network? Im guessing that if your trying to communicate across multiple vlans you may need to have the relay agent in place so that the dhcp server knows where those clients reside. This article may be helpful in solving your problem:

http://www.serverwatch.com/tutorials/article.php/2193031/Back-to-Basics-The-DHCP-Relay-Agent.htm

0
 

Author Comment

by:jjl505
ID: 33511512
I will have a loook at the article and get back to you.  Thank you for the prompt response.
0
Better Security Awareness With Threat Intelligence

See how one of the leading financial services organizations uses Recorded Future as part of a holistic threat intelligence program to promote security awareness and proactively and efficiently identify threats.

 
LVL 2

Accepted Solution

by:
pmanno earned 500 total points
ID: 33524431
DHCP is a broadcast based protocol.  In order for it to work, all machines (client and server) must be in the same broadcast domain.  A firewall/router does not pass broadcast traffic unless it is configured to relay that traffic through in which case it takes the DHCP request and forwards it to one or more servers.

What firewall are you using?  If SonicWall, look at Network -> IP Helper for the configuration of the relay.
0
 
LVL 9

Expert Comment

by:Donboo
ID: 33526250
Looks very much like you problem is the firewall that is not configured to relay the dhcp request.

Check the firewall see if you have configured DHCP relay agent/ IP-helper.

What firewall are you using?
0
 

Author Comment

by:jjl505
ID: 33526516
A Fortinet Fortigate...I will have our Security guy take a look at it.
0
 

Author Comment

by:jjl505
ID: 33627960
It was a firewall issue.  DHCP relaying was not enabled.  I think a thorough beating is in order.
0
 
LVL 2

Expert Comment

by:pmanno
ID: 33627988
Dude, no points!?  I put up DHCP relay...
0

Featured Post

What Should I Do With This Threat Intelligence?

Are you wondering if you actually need threat intelligence? The answer is yes. We explain the basics for creating useful threat intelligence.

Join & Write a Comment

I see many questions here on Experts Exchange regarding switch port configurations and trunks. This article is meant for beginners in the subject to help to get basic knowledge about Virtual Local Area Network (VLAN (http://en.wikipedia.org/wiki/Vir…
I eventually solved a perplexing problem setting up telnet for a new switch.  I installed a new Cisco WS-03560X-24P switch connected to an existing Cisco 4506 running a WS-X4013-10GE Sup II-Plus. After configuring vlans and trunking,  I could no…
Here's a very brief overview of the methods PRTG Network Monitor (https://www.paessler.com/prtg) offers for monitoring bandwidth, to help you decide which methods you´d like to investigate in more detail.  The methods are covered in more detail in o…
This video demonstrates how to create an example email signature rule for a department in a company using CodeTwo Exchange Rules. The signature will be inserted beneath users' latest emails in conversations and will be displayed in users' Sent Items…

762 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

20 Experts available now in Live!

Get 1:1 Help Now