Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.


Paul1977

5041 posts

Uber Geek


#290400 9-Nov-2021 09:42
Send private message

I'm not sure if this is the best forum for this, as I'm having trouble identifying whether it's a networking issue or a DHCP server issue.

 

  • DHCP server is Windows 2019 at main site in subnet A and is configured with scopes for all subnets.
  • Branch site 1 has two subnets B & C
  • Branch site 2 has two subnets D & E
  • Branch site 3 has one subnet F

Subnets aren't VLANs, they are physical subnets with routers between them. Branch sites are connected to main site via site-to-site IPsec VPNs.

 

Everythings is working perfectly, except DHCP relay from some subnets isn't working...

 

  • Subnets B, C, & D DHCP relay works
  • Subnets E & F DHCP relay doesn't work

When I attempt to obtain an IP address for a client in subnet F (for example) I can see that DHCP traffic (UDP 67/68) is passing through the router at the main site, but the client times out and doesn't get an address.

 

If I manually assign an address to the client (or set up a local DHCP server to issue addresses) full communication between subnets E/F and A works.

 

For testing I've allowed unrestricted traffic between Subnet A and E/F, and have ensured that the Windows Firewall on the DHCP server is not restricting incoming traffic to UDP ports 67/68.

 

I'm at a complete loss as I can't see any difference between the subnets/scopes that are working and those that aren't.





 Home:                                                           Work:
Home Work


Create new topic
Dynamic
3866 posts

Uber Geek

ID Verified
Trusted
Lifetime subscriber

  #2809769 9-Nov-2021 09:57
Send private message

We've always had DHCP on each site in case links go down, so I can't comment specifically on troubleshooting this beyond generic thoughts.

 

Can you turn up logging levels to maximum and see if that reveals anything?  Ideally aiming to compare a complete DHCP transaction to an incomplete transaction.  That would hopefully reveal whether the requests are actually making it to the server and the response is not getting back to the client.

 

I'm picking it is something subtly different in the routing rules, perhaps even just the order of the rules influencing how the traffic is handled.  Good luck!





“Don't believe anything you read on the net. Except this. Well, including this, I suppose.” Douglas Adams

 

Referral links to services I use, really like, and may be rewarded if you sign up:
PocketSmith for budgeting and personal finance management.  A great Kiwi company.




MadEngineer
4271 posts

Uber Geek

Trusted

  #2809770 9-Nov-2021 10:06
Send private message

Use wire shark. You’ll see all the faults clear as day




You're not on Atlantis anymore, Duncan Idaho.

Paul1977

5041 posts

Uber Geek


  #2809896 9-Nov-2021 14:27
Send private message

OK, so turns out the dhcp-relay function on EdgeRouters doesn't work over a VTI interface. Worked around it by using the dhcp-relay option built into dnsmasq.

 

But interestingly that means I had two different problems, as none of the other sites use EdgeRouters. I mistakenly thought it would be a the same issue, but I'm half way there.


Create new topic





News and reviews »

Air New Zealand Starts AI adoption with OpenAI
Posted 24-Jul-2025 16:00


eero Pro 7 Review
Posted 23-Jul-2025 12:07


BeeStation Plus Review
Posted 21-Jul-2025 14:21


eero Unveils New Wi-Fi 7 Products in New Zealand
Posted 21-Jul-2025 00:01


WiZ Introduces HDMI Sync Box and other Light Devices
Posted 20-Jul-2025 17:32


RedShield Enhances DDoS and Bot Attack Protection
Posted 20-Jul-2025 17:26


Seagate Ships 30TB Drives
Posted 17-Jul-2025 11:24


Oclean AirPump A10 Water Flosser Review
Posted 13-Jul-2025 11:05


Samsung Galaxy Z Fold7: Raising the Bar for Smartphones
Posted 10-Jul-2025 02:01


Samsung Galaxy Z Flip7 Brings New Edge-To-Edge FlexWindow
Posted 10-Jul-2025 02:01


Epson Launches New AM-C550Z WorkForce Enterprise printer
Posted 9-Jul-2025 18:22


Samsung Releases Smart Monitor M9
Posted 9-Jul-2025 17:46


Nearly Half of Older Kiwis Still Write their Passwords on Paper
Posted 9-Jul-2025 08:42


D-Link 4G+ Cat6 Wi-Fi 6 DWR-933M Mobile Hotspot Review
Posted 1-Jul-2025 11:34


Oppo A5 Series Launches With New Levels of Durability
Posted 30-Jun-2025 10:15









Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.



Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.