XS3800 IP Source Guard Lease time update issue.

Options
Eugene0x1
Eugene0x1 Posts: 5
edited August 2022 in Switch

There is a switch XS3800-28 with the firmware version 4.70(ABML.1).

DHCP snooping, IP Source Guard, and ARP Inspection are configured on the device.

DHCP server is standalone device and XS3800-28 works as DHCP relay.

When user’s computer receives IP address, a new record appears in the IP Source Guard table.

Everything works fine until the Lease time is expired.

 

As soon as Lease time expires the MAC address is placed into the filtering table. I have figured out that re-new of IP address does not update the Lease time in the IP Source Guard table. If cable from user’s computer is disconnected and connected back, everything is updated and works fine. Moreover, if ipconfig /release and ipconfig /renew are executed on user’s Windows computers, the problem solves as well. But only ipconfig /renew command update Lease time only on the local computer and DHCP server, but Lease time is not updated in the IP Source Guard table.

 

Could you please advise how to solve the problem?

Accepted Solution

  • Zyxel_Chris
    Zyxel_Chris Posts: 660  Zyxel Employee
    First Anniversary 10 Comments Friend Collector First Answer
    Answer ✓
    Options
    @Eugene0x1
    Hello,
    As I check the log, DHCP server is located on VLAN12 and in usual case we put DHCP sever's VLAN to the DHCP snooping setting, please bind VLAN12 to it and help to provide the tech support file if the issue still persists.
    Chris
«1

All Replies

  • Zyxel_Chris
    Zyxel_Chris Posts: 660  Zyxel Employee
    First Anniversary 10 Comments Friend Collector First Answer
    Options
    @Eugene0x1
    In general, when the lease time remains at the half, for instance, the lease time is 10 minutes, the client will send DHCP request to renew the IP after 5 minute and DHCP server will answer the ack to the client.

    You have mentioned that "As soon as Lease time expires the MAC address is placed into the filtering table." I assume you mean your lease time will run out to 0.
    If it is the case then your DHCP server may not answer the call when the client tries to renew or the client does not send the renewal after the half of lease time.

    Chris
  • Eugene0x1
    Eugene0x1 Posts: 5
    Options

    Dear Chris,

    When ipconfig /renew executed manually on the Windows computer the leas time is updated on the client computer, it can be seen in the properties of a network adapter. The same time lease time for the record of this client is updated on the DHCP server as well. In other words, both client and DHCP server update their lease time, it means that interaction happens successfully. Only XS3800-28 does not update the lease time. The DHCP server is configured on a Mikrotik device.


  • PeterUK
    PeterUK Posts: 2,709  Guru Member
    First Anniversary 10 Comments Friend Collector First Answer
    Options

    Can you block the client from requesting of the server IP this way the client will Rebinding and broadcast the a request for renew.


  • Eugene0x1
    Eugene0x1 Posts: 5
    Options

    Dear PeterUK,

    Unfortunately, the blocking of the request from the clients is not possible. Is it well known issue that XS3800-28 ignores DHCP renew requests?

  • PeterUK
    PeterUK Posts: 2,709  Guru Member
    First Anniversary 10 Comments Friend Collector First Answer
    Options

    My GS2210-24 works fine with IP Source Guard but then the firmware is likely not the same code.

    Are you able to test another DHCP server?

    Maybe the XS3800-28 is not snooping ACK and only sees OFFERS?


  • Zyxel_Chris
    Zyxel_Chris Posts: 660  Zyxel Employee
    First Anniversary 10 Comments Friend Collector First Answer
    Options
    @Eugene0x1
    I have use the Mikrotik routerboard 450G to try to reproduce this issue however, ipconfig/renew can work and also can get IP when the lease time is expired. 
    Could you PM me your tech support file? I would like to check your configuration.
    In management> maintenance> tech support
    Chris
  • dkyeager
    dkyeager Posts: 69  Ally Member
    First Anniversary 10 Comments Friend Collector
    Options
    4.80 firmware is now posted.  Perhaps...
  • Zyxel_Chris
    Zyxel_Chris Posts: 660  Zyxel Employee
    First Anniversary 10 Comments Friend Collector First Answer
    Options
    @Eugene0x1
    It's been a while, may I know if the issue still persists if so please private message me the tech support file as I required last time.  :)
    Chris
  • Eugene0x1
    Options
    Dear Chris,

    Sorry for the delay. I have sent a private message to you.
  • Zyxel_Chris
    Zyxel_Chris Posts: 660  Zyxel Employee
    First Anniversary 10 Comments Friend Collector First Answer
    Answer ✓
    Options
    @Eugene0x1
    Hello,
    As I check the log, DHCP server is located on VLAN12 and in usual case we put DHCP sever's VLAN to the DHCP snooping setting, please bind VLAN12 to it and help to provide the tech support file if the issue still persists.
    Chris