?
Solved

DHCP Relay not working

Posted on 2011-02-22
5
Medium Priority
?
1,419 Views
Last Modified: 2013-11-16
I am running two Checkpoint UTM-1 270s running NGX R65 in a HA cluster.  On the external interface, besides my primary ISP (not a VLAN) I have 5 other VLANs, including another ISP and 3 private connections from our ISP (COX) on MetroE.  Two of these MetroE connections are with partners, and are completely NATted, with no internal access.  The third is with a new branch office. DHCP requests from the new office are not being forwarded to the Windows AD DC.

I have turned on DHCP relay in the Expert Mode of both firewalls, and enabled it both on the External and the External.210 interfaces, but no luck.  Seems like this should be pretty straight forward, but I am beating my head against the wall here.

David Griswold
0
Comment
Question by:david_griswold
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
5 Comments
 

Assisted Solution

by:david_griswold
david_griswold earned 0 total points
ID: 34955288
After reading a bit more, I realized I didn't have a firewall rule to allow the DHCP broadcasts, requests and responses, so I setup a wide open one, just to get the requests forwarded.  I see in the logs that they are being forwarded to the server, and the server is getting back to the firewall, but that's where it ends.  The client never gets the response back.

David
0
 
LVL 3

Expert Comment

by:Rick_at_ptscinti
ID: 34956088
I am not a Checkpoint guy but on most routers you just have to specify a helper address on LAN interface of the far router.  (the helper address is the IP address of the DHCP server)  You shouldn't have to do anything on the server side network.  I know on some routers you can't have DHCP running on the router as well as use helper addresses.
0
 

Accepted Solution

by:
david_griswold earned 0 total points
ID: 34956391
There is only one helper in the path.  I already ruled that one out.

I figured it out.  I had DHCP relay turned on the Internal interface, but not the interface that the DHCP response was returning on, which was Internal.30.  Once I enabled DHCP relay on that interface, it started working.

Now I just need to figure out why stateful connections, like SQL and others are getting reset periodically, but that is another question...
0
 

Author Comment

by:david_griswold
ID: 34956407
closed
0
 

Author Closing Comment

by:david_griswold
ID: 34990880
I figured it out on my own.
0

Featured Post

On Demand Webinar: Networking for the Cloud Era

Did you know SD-WANs can improve network connectivity? Check out this webinar to learn how an SD-WAN simplified, one-click tool can help you migrate and manage data in the cloud.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Do you have a windows based Checkpoint SmartCenter for centralized Checkpoint management?  Have you ever backed up the firewall policy residing on the SmartCenter?  If you have then you know the hassles of connecting to the server, doing an upgrade_…
The DROP (Spamhaus Don't Route Or Peer List) is a small list of IP address ranges that have been stolen or hijacked from their rightful owners. The DROP list is not a DNS based list.  It is designed to be downloaded as a file, with primary intention…
This is my first video review of Microsoft Bookings, I will be doing a part two with a bit more information, but wanted to get this out to you folks.
In this video, Percona Solution Engineer Dimitri Vanoverbeke discusses why you want to use at least three nodes in a database cluster. To discuss how Percona Consulting can help with your design and architecture needs for your database and infras…
Suggested Courses
Course of the Month13 days, 17 hours left to enroll

801 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question