Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people, just like you, are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
Solved

DHCP Relay not working

Posted on 2011-02-22
5
1,413 Views
Last Modified: 2013-11-16
I am running two Checkpoint UTM-1 270s running NGX R65 in a HA cluster.  On the external interface, besides my primary ISP (not a VLAN) I have 5 other VLANs, including another ISP and 3 private connections from our ISP (COX) on MetroE.  Two of these MetroE connections are with partners, and are completely NATted, with no internal access.  The third is with a new branch office. DHCP requests from the new office are not being forwarded to the Windows AD DC.

I have turned on DHCP relay in the Expert Mode of both firewalls, and enabled it both on the External and the External.210 interfaces, but no luck.  Seems like this should be pretty straight forward, but I am beating my head against the wall here.

David Griswold
0
Comment
Question by:david_griswold
  • 4
5 Comments
 

Assisted Solution

by:david_griswold
david_griswold earned 0 total points
ID: 34955288
After reading a bit more, I realized I didn't have a firewall rule to allow the DHCP broadcasts, requests and responses, so I setup a wide open one, just to get the requests forwarded.  I see in the logs that they are being forwarded to the server, and the server is getting back to the firewall, but that's where it ends.  The client never gets the response back.

David
0
 
LVL 3

Expert Comment

by:Rick_at_ptscinti
ID: 34956088
I am not a Checkpoint guy but on most routers you just have to specify a helper address on LAN interface of the far router.  (the helper address is the IP address of the DHCP server)  You shouldn't have to do anything on the server side network.  I know on some routers you can't have DHCP running on the router as well as use helper addresses.
0
 

Accepted Solution

by:
david_griswold earned 0 total points
ID: 34956391
There is only one helper in the path.  I already ruled that one out.

I figured it out.  I had DHCP relay turned on the Internal interface, but not the interface that the DHCP response was returning on, which was Internal.30.  Once I enabled DHCP relay on that interface, it started working.

Now I just need to figure out why stateful connections, like SQL and others are getting reset periodically, but that is another question...
0
 

Author Comment

by:david_griswold
ID: 34956407
closed
0
 

Author Closing Comment

by:david_griswold
ID: 34990880
I figured it out on my own.
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
exact syntax to permit ipfilter rules in Solaris 10 x86 2 69
VPN client software 7 56
Blocking  of URL on mcafee sidewinder firewall 3 61
SQL Server Communications Audit 5 110
Wikipedia defines 'Script Kiddies' in this informal way: "In hacker culture, a script kiddie, occasionally script bunny, skiddie, script kitty, script-running juvenile (SRJ), or similar, is a derogatory term used to describe those who use scripts or…
If you are like regular user of computer nowadays, a good bet that your home computer is on right now, all exposed to world of Internet to be exploited by somebody you do not know and you never will. Internet security issues has been getting worse d…
Microsoft Active Directory, the widely used IT infrastructure, is known for its high risk of credential theft. The best way to test your Active Directory’s vulnerabilities to pass-the-ticket, pass-the-hash, privilege escalation, and malware attacks …
Email security requires an ever evolving service that stays up to date with counter-evolving threats. The Email Laundry perform Research and Development to ensure their email security service evolves faster than cyber criminals. We apply our Threat…

856 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question