USG110 - DHCP Discover failed on WAN1 Port
Presently we're experiencing failed DHCP lease renewals with our ISP1 on WAN1. We have the following general configuration:
WAN1: connected to a Cisco Switch (owned by ISP1) where the fiber line (100/100 Mbit) is connected to. IP address will be obtained by DHCP.
WAN2: connected to a router (owned by ISP2) where DSL (50/10 Mbit) is connected to. Fixed IP is set at USG and assigned fixed IP from ISP2 is set at Fritzbox.
WAN2 should work as failover line only, means without configuring any BWM.
Further we have a WAN trunk failover procedure in place:
And finally the failover will be triggered by a regular connectivity check on WAN1 as follows:
In general it works fine, but during the last days our WAN1 connection gets regularly lost. It has been turned out, that we could make a manual RENEW to get back our IP address and the connection. That's why we know that there is something wrong with the DHCP conversation.
Our ISP says, the problem is on our side. In general, and allthough we got a fix IP address, this IP has to be renewed regularly by DHCP about every 2h. Configuring the fix IP in our USG doesn't work. Not nice, but OK. It's a requirement of the ISP.
But often the ISP DHCP Server returns a DHCP_NAK to our DHCP_REQUEST. And on a NAK packet the USG should normally start a complete new DHCP_DISCOVER. But it doesn't. And in that case we lost our connection. This has been checked by WireShark from ISP side.
Unfortunately this cannot be intentionally reproduced. Mostly the DHCP server is returning a DHCP_ACK to our DHCP_REQUEST to renew the lease. But even sometimes also a DHCP_NAK without further reaction from USG.
Has anybody experienced similar problems with DHCP?
We also thought about our WAN1 connectivity check. Could it interfere the DHCP renewal process when a simultaneously made connectivity check failed while the DHCP server is responding a NAK and thatswhy WAN1 is loosing its IP for a short time? In that case the USG failover procedure might switching-over to WAN2 and the IP renewal on WAN1 could not be finished. I know it's far-fetched.
- 5.7K All Categories
- 1.1K Nebula
- 14 Nebula Ideas
- 9 Nebula Status and Incidents
- 3.2K Security
- 173 Security Ideas
- 571 Switch
- 25 Switch Ideas
- 393 WirelessLAN
- 3 WLAN Ideas
- 4.1K Consumer Product
- 43 Service & License
- 178 New and Release
- 35 Stories
- 23 Security Advisories
- 443 FAQ
- 202 Nebula FAQ
- 97 Security FAQ
- 65 Switch FAQ
- 63 WirelessLAN FAQ
- 20 Nebula Monthly Express
- 27 About Community
- 17 Security Highlight