DHCP relay not working over site-to-site VPN on FLEX 200H
Freshman Member
We operate a network with approximately twelve branch offices and a centralized server infrastructure at our headquarters.
All branch offices are connected to the headquarters via site-to-site VPN tunnels. The branches contain only Windows clients, while DHCP is provided centrally by a Windows DHCP server at the headquarters. The routers at the branch offices act as DHCP relay agents and forward the DHCP requests through the VPN tunnel.
This setup has worked reliably for years with Zyxel USG devices and previous FLEX models.
However, DHCP relay does not work at a branch office using a FLEX 200H. The device is running the latest firmware, and DHCP relay has been configured on the relevant Ethernet interface in the same way as on our other Zyxel firewalls.
Normally, we only need to enable DHCP relay and specify the IP address of the central DHCP server. On the FLEX 200H, however, no DHCP requests appear to reach the server through the site-to-site VPN tunnel.
The result is the same whether the new “Upstream Interface” option is configured or left unset.
Has anyone successfully configured DHCP relay over a site-to-site VPN on a FLEX H-series device? Is there an additional routing, firewall, or VPN setting required, or is this a known issue?
All Replies
-
There are things that like you say did work on ZLD and not the FLEX H uOS with any luck these missing methods can be added back.
You might have some luck if instead of site-to-site VPN do a VTI VPN
0 -
Hi @MyForumUser ,
To help you investigate this symptom, please provide the Nebula organization & site name and enable Zyxel Support.
Zyxel_Judy
0 -
Hi Judy,
I opened a support case refering to this post and Zyxel Support is enabled.0 -
Hi @MyForumUser ,
We replied to your ticket email. Please let us know the result after you reconfigure your DHCP relay and VPN.
Zyxel_Judy
0 -
Hi Judy,
we now had the time to dive into this.
And yes, to build route based vpn instead of policy based did the trick.Thank you.
0 -
Hi @MyForumUser ,
Thank you for your update. Let us summary the case here:
If you would like the firewall to initiate the traffic and forward it through the VPN tunnel, you need to configure the VPN as a Route-Based VPN.
After you configure the DHCP Relay function on the appropriate interface first, then reconfigure the VPN as a Route-Based VPN, the DHCP relay works over site-to-site VPN.Zyxel_Judy
0
Categories
- All Categories
- 442 Beta Program
- 3.1K Nebula
- 234 Nebula Ideas
- 6.7K Security
- 706 USG FLEX H Series
- 369 Security Ideas
- 1.8K Switch
- 87 Switch Ideas
- 1.4K Wireless
- 56 Wireless Ideas
- 7.1K Consumer Product
- 313 Service & License
- 512 News and Release
- 99 Security Advisories
- 31 Education Center
- 10 [Campaign] Zyxel Network Detective
- 5.2K FAQ
- 34 Documents
- 89 About Community
- 116 Security Highlight
Guru Member
Zyxel Employee