DHCP relay not working over site-to-site VPN on FLEX 200H

Options
MyForumUser
MyForumUser Posts: 11 image  Freshman Member
First Comment Friend Collector Fifth Anniversary

We operate a network with approximately twelve branch offices and a centralized server infrastructure at our headquarters.

All branch offices are connected to the headquarters via site-to-site VPN tunnels. The branches contain only Windows clients, while DHCP is provided centrally by a Windows DHCP server at the headquarters. The routers at the branch offices act as DHCP relay agents and forward the DHCP requests through the VPN tunnel.

This setup has worked reliably for years with Zyxel USG devices and previous FLEX models.

However, DHCP relay does not work at a branch office using a FLEX 200H. The device is running the latest firmware, and DHCP relay has been configured on the relevant Ethernet interface in the same way as on our other Zyxel firewalls.

Normally, we only need to enable DHCP relay and specify the IP address of the central DHCP server. On the FLEX 200H, however, no DHCP requests appear to reach the server through the site-to-site VPN tunnel.

The result is the same whether the new “Upstream Interface” option is configured or left unset.

Has anyone successfully configured DHCP relay over a site-to-site VPN on a FLEX H-series device? Is there an additional routing, firewall, or VPN setting required, or is this a known issue?

All Replies

  • PeterUK
    PeterUK Posts: 4,608 image  Guru Member
    250 Answers 2500 Comments Friend Collector Eighth Anniversary
    edited July 15
    Options

    There are things that like you say did work on ZLD and not the FLEX H uOS with any luck these missing methods can be added back.

    You might have some luck if instead of site-to-site VPN do a VTI VPN

  • Zyxel_Judy
    Zyxel_Judy Posts: 2,626 image  Zyxel Employee
    Zyxel Certified Network Engineer Level 2 - Nebula Zyxel Certified Network Engineer Level 2 - Switch Zyxel Certified Network Engineer Level 2 - Security Zyxel Certified Network Engineer Level 1 - Nebula
    Options

    Hi @MyForumUser ,

    To help you investigate this symptom, please provide the Nebula organization & site name and enable Zyxel Support.

    Zyxel_Judy

  • MyForumUser
    MyForumUser Posts: 11 image  Freshman Member
    First Comment Friend Collector Fifth Anniversary
    Options

    Hi Judy,
    I opened a support case refering to this post and Zyxel Support is enabled.

  • Zyxel_Judy
    Zyxel_Judy Posts: 2,626 image  Zyxel Employee
    Zyxel Certified Network Engineer Level 2 - Nebula Zyxel Certified Network Engineer Level 2 - Switch Zyxel Certified Network Engineer Level 2 - Security Zyxel Certified Network Engineer Level 1 - Nebula
    Options

    Hi @MyForumUser ,

    We replied to your ticket email. Please let us know the result after you reconfigure your DHCP relay and VPN.

    Zyxel_Judy

  • MyForumUser
    MyForumUser Posts: 11 image  Freshman Member
    First Comment Friend Collector Fifth Anniversary
    Options

    Hi Judy,
    we now had the time to dive into this.
    And yes, to build route based vpn instead of policy based did the trick.

    Thank you.

  • Zyxel_Judy
    Zyxel_Judy Posts: 2,626 image  Zyxel Employee
    Zyxel Certified Network Engineer Level 2 - Nebula Zyxel Certified Network Engineer Level 2 - Switch Zyxel Certified Network Engineer Level 2 - Security Zyxel Certified Network Engineer Level 1 - Nebula
    Options

    Hi @MyForumUser ,

    Thank you for your update. Let us summary the case here:
    If you would like the firewall to initiate the traffic and forward it through the VPN tunnel, you need to configure the VPN as a Route-Based VPN.
    After you configure the DHCP Relay function on the appropriate interface first, then reconfigure the VPN as a Route-Based VPN, the DHCP relay works over site-to-site VPN.

    Zyxel_Judy