Multiple DHCP Server Offers from Multiple VLAN's

Got_Signal
Got_Signal Posts: 6  Freshman Member
First Comment Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate
edited June 14 in Security

I have a new setup with basic firewall rules and multiple VLAN's. Setup is as follows:

Modem → USG Flex 200(V5.38(ABFW.0)) → XS1930-12HP(V4.80(ABQF.3)) → NWA130BE(V6.75(ACIL.0)) or WBE660S(V6.70(ACGG.3))

The issue is a device will request a DHCP, and two different DHCP Servers from two different VLAN's are answering. More often than not, the wrong VLAN Server wins, creating devices with IP Addresses in the wrong subnet. See image below, some information removed.

All of these devices are connected to an SSID with VLAN 140 (10.140.0.1), but some of them are receiving IP Addresses from a temporary VLAN 300 (192.168.1.1).

Flex logs show a request and two offers, see below:

2024-06-14 15:26:29 DHCP DHCP server offered 192.168.1.26 to (4C:BA:D7:XX:XX:XX)
2024-06-14 15:26:29 DHCP DHCP server offered 10.140.0.16 to (4C:BA:D7:XX:XX:XX)
2024-06-14 15:26:29 DHCP Requested 192.168.1.26 from LG_Smart_Oven2_open(4C:BA:D7:XX:XX:XX)
2024-06-14 15:26:29 DHCP Requested 192.168.1.26 from (4C:BA:D7:XX:XX:XX)

The printers specifically are Static DHCP assigned in the VLAN 140 Table, but are getting VLAN 300 IP Addresses.

There are no Static Routes Defined, No Traffic Shaping, with Basic Security Policies for Content Filtering and allowing the printers to communicate across VLANS.

Any input on where to look is appreciated. I've never come across this before.

Edit: Removed some MAC Data, also wanted to note that all hardware has been rebooted and still has not resolved issue.

Also, the switch ports are set to Trunk and allow All VLANs, also VLAN 300 is not assigned to any WiFi SSID, only LAN.

Accepted Solution

  • Got_Signal
    Got_Signal Posts: 6  Freshman Member
    First Comment Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate
    Answer ✓

    False alarm, sorry everyone. Someone looped two switches, which was resolved with some new settings and physically verifying and removing the patched cable.

All Replies

  • PeterUK
    PeterUK Posts: 3,161  Guru Member
    Community MVP 2500 Comments Sixth Anniversary 100 Answers
    edited June 14

    If you connect the AP to the Flex 200 without switch does the problem happen? or connect a PC with VLAN140 to the switch in place of the AP?

  • Got_Signal
    Got_Signal Posts: 6  Freshman Member
    First Comment Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate

    I've been digging into this remotely, and it would appear that someone may have plugged in creating a loop between switches and vlans. I will update once I get onsite and physically assess.

  • Got_Signal
    Got_Signal Posts: 6  Freshman Member
    First Comment Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate
    Answer ✓

    False alarm, sorry everyone. Someone looped two switches, which was resolved with some new settings and physically verifying and removing the patched cable.

Security Highlight