Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.


yumcimil

177 posts

Master Geek


#259729 17-Oct-2019 22:27
Send private message

The Orcon-provided router works just fine. Trying to use a FG-60E instead. :)

 

I've just switched across to Orcon from My Republic, and my DHCP issues with my Fortigate 60E appear to have followed along. It does not appear to get a DHCP lease. With My Republic, it never even saw a DHCP offer. Under Orcon, I'm seeing the offer, and sending the request back, but never getting the acknowledgement.

 

The issue originally began randomly about three weeks ago with My Republic, and their first level guys said they'd had another fortigate user with the same issue recently.

 

The Fortigate happily gets a DHCP lease from LAN-based sources, but very definitely hates anything coming out of the ONT - it had been running fine for months. Any ideas/other people in the same boat? Packet capture attached.


View this topic in a long page with up to 500 replies per page Create new topic
 1 | 2
nbroad
320 posts

Ultimate Geek


  #2339987 18-Oct-2019 08:31
Send private message

VLAN tagging?

 

I can't see the packet capture attached.

 

Cheers




networkn
Networkn
32358 posts

Uber Geek

ID Verified
Trusted
Lifetime subscriber

  #2339988 18-Oct-2019 08:33
Send private message

I have just put a 60E in my own environment which is Orcon gigabit fibre and I had a 30e for the past couple of weeks, and no issues with dhcp, since installing the FG's I have had slow arp updates across all my devices for a reason not apparent. 

 

 

 

What firmware version? I am on 6.x I had 6.2 on the 30e but this 60E is 6.0 something I think. Neither had any issues getting IP from Orcon, though mine is static.

 

You have your WAN plugged in and a new virtual interface with a VLAN 10 set?

 

 


fsecurity
16 posts

Geek

ID Verified
Trusted

#2340129 18-Oct-2019 12:13
Send private message

I’ve had this exact problem with several juniper SRX series firewalls. I’ve had them working, then after a power outage I send countless DHCP requests but never receive an offer. Plug a Mac or PC in and you get a DHCP lease no problem, then all of a sudden after a week or two you plug in the SRX and it magically works. I’ve tried this with older SRX110s and SRX220s running legacy code, and my modern SRX300 with recommended releases - same result every time. Something appears to be going on with MyRepublics BNG/DHCP server. Unfortunately their technical support for this kind of issue is pretty bad, I’ve tried to provide packet dumps and get a engineer on the phone but no luck.



yumcimil

177 posts

Master Geek


  #2340139 18-Oct-2019 12:38
Send private message

With more link!

https://drive.google.com/a/kablooey.co.nz/file/d/1-9fBsNNz9znFHgkDRgiYkn85eXjYozUF/view?usp=drivesdk

yumcimil

177 posts

Master Geek


  #2340140 18-Oct-2019 12:51
Send private message

Yeah. I literally had an email from my Republics engineer asking for packet caps the day Orcon. Hopefully Orcon are more helpful. It's definitely a weird one though.

LennonNZ
2459 posts

Uber Geek

ID Verified
Trusted

  #2340147 18-Oct-2019 13:45
Send private message

It may be the Fortigate is sending a 802.1p COS or something which the UFB network is dropping.. I have requested access of the file but what is 801.p value being sent out...?

 

 


Sounddude
I fix stuff!
1928 posts

Uber Geek

Trusted
2degrees
Lifetime subscriber

  #2340148 18-Oct-2019 13:54
Send private message

Josh? :-) Long time if it is :-)

 

PM me your details and I can look at the logs for you.


 
 
 

Trade NZ and US shares and funds with Sharesies (affiliate link).
yumcimil

177 posts

Master Geek


  #2340359 18-Oct-2019 19:56
Send private message

Sup!

 

Lennon - Access is fixed, sorry about that. :)

 

Will provide customer details shortly.


LennonNZ
2459 posts

Uber Geek

ID Verified
Trusted

  #2340363 18-Oct-2019 20:07
Send private message

Having a quick look .. it seems a standard DHCP request/offer but after the offer the fortinet is ignoring/not accepting the offer. 

 

Maybe turn on logging/updating to latest version/check bugs on existing firmware version. Apart from that I really can't help.

 

 


networkn
Networkn
32358 posts

Uber Geek

ID Verified
Trusted
Lifetime subscriber

  #2340364 18-Oct-2019 20:14
Send private message

So to confirm, the capture has been sent to Fortinet for analysis with a support ticket? As a new partner I am keen to see how they resolve this. 

 

 


Sounddude
I fix stuff!
1928 posts

Uber Geek

Trusted
2degrees
Lifetime subscriber

  #2340366 18-Oct-2019 20:26
Send private message

Looking at the pcap file, the DHCP packet is not being framed with 802.1q.

 

We expect the dhcp packet to be tagged with vlan 10.

 

 

 

 


networkn
Networkn
32358 posts

Uber Geek

ID Verified
Trusted
Lifetime subscriber

  #2340372 18-Oct-2019 20:35
Send private message

Sounddude:

 

Looking at the pcap file, the DHCP packet is not being framed with 802.1q.

 

We expect the dhcp packet to be tagged with vlan 10.

 

 

 

 

 

 

 

 

OP are you sure you have a virtual interface added to your WAN Interface?

 

 

 

 

 

As a reference. 

 

I assume you have, but just in case....


LennonNZ
2459 posts

Uber Geek

ID Verified
Trusted

  #2340381 18-Oct-2019 21:08
Send private message

The dump may be done on VLAN 10, not on the raw interface so you might not see the VLAN tag.

 

This may help with  debugging if it works on your fortinet.

 

https://kb.fortinet.com/kb/documentLink.do?externalID=FD30879

 

 

 

 


yumcimil

177 posts

Master Geek


  #2341177 21-Oct-2019 08:35
Send private message

Sounddude:

 

Looking at the pcap file, the DHCP packet is not being framed with 802.1q.

 

We expect the dhcp packet to be tagged with vlan 10.

 

 

 

 

 

 

Was certainly meant to be. Will double-check tonight and post config.


yumcimil

177 posts

Master Geek


  #2341179 21-Oct-2019 08:39
Send private message

networkn:

 

So to confirm, the capture has been sent to Fortinet for analysis with a support ticket? As a new partner I am keen to see how they resolve this. 

 

 

 

 

Yeah, we're in the same boat. I used some of my training budget to buy one for home via NFR. Going to see how we go with logging the ticket today (Last week was Kawaiicon).


 1 | 2
View this topic in a long page with up to 500 replies per page Create new topic





News and reviews »

Air New Zealand Starts AI adoption with OpenAI
Posted 24-Jul-2025 16:00


eero Pro 7 Review
Posted 23-Jul-2025 12:07


BeeStation Plus Review
Posted 21-Jul-2025 14:21


eero Unveils New Wi-Fi 7 Products in New Zealand
Posted 21-Jul-2025 00:01


WiZ Introduces HDMI Sync Box and other Light Devices
Posted 20-Jul-2025 17:32


RedShield Enhances DDoS and Bot Attack Protection
Posted 20-Jul-2025 17:26


Seagate Ships 30TB Drives
Posted 17-Jul-2025 11:24


Oclean AirPump A10 Water Flosser Review
Posted 13-Jul-2025 11:05


Samsung Galaxy Z Fold7: Raising the Bar for Smartphones
Posted 10-Jul-2025 02:01


Samsung Galaxy Z Flip7 Brings New Edge-To-Edge FlexWindow
Posted 10-Jul-2025 02:01


Epson Launches New AM-C550Z WorkForce Enterprise printer
Posted 9-Jul-2025 18:22


Samsung Releases Smart Monitor M9
Posted 9-Jul-2025 17:46


Nearly Half of Older Kiwis Still Write their Passwords on Paper
Posted 9-Jul-2025 08:42


D-Link 4G+ Cat6 Wi-Fi 6 DWR-933M Mobile Hotspot Review
Posted 1-Jul-2025 11:34


Oppo A5 Series Launches With New Levels of Durability
Posted 30-Jun-2025 10:15









Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.



Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.