DHCP Relay Agent not working

Newbie184795 Lv1Posted Jan-28-2025 11:56

We have a Sangfor NGAF already setup internal DHCP scope 192.168.18.10 to 100.  I also setup internal DHCP relay scope on our Windows DHCP Server 192.168.18.101 to 200.

The Windows DHCP service sure working no issue, as I have also setup another scopes.  It is running fine.
Now the issue the client machine cannot thru relay agent to get the IP from Windows DHCP server, but OK to get from Sangfor internal DHCP server.

Our main goal wants to migrate and centralize all DHCP scopes to one Windows DHCP server (not some scopes at Windows and some at Sangfor)

By solving this question, you may help 938 user(s).

Posting a reply earns you 2 coins. An accepted reply earns you 20 coins and another 10 coins for replying within 10 minutes. (Expired) What is Coin?

Enter your mobile phone number and company name for better service. Go

CLELUQMAN Lv4Posted Jan-28-2025 14:06
  
can provide some screenshot?
Farina Ahmed Lv5Posted Jan-28-2025 15:44
  
Check if firewall rules allow DHCP traffic between the devices. Double-check the relay configuration and IP helper addresses on the NGAF.
Darjo Lv1Posted Jan-28-2025 16:39
  

makesure you already choosed DHCP Relay on NGAF, select interface that can reachable to DHCP Server and fill IP address of DHCP Server

This topic contains more resources

You must log in to download or view the file. Not registered yet? Register

x
Newbie184795 Lv1Posted Feb-05-2025 14:17
  
Hi,

Just back from CNY holiday.
I would like to provide below two screenshots and there is no ACL for two subnets (192.168.10.0/24 and 192.168.18.0/24).  All traffic is passing in Intranet.




This topic contains more resources

You must log in to download or view the file. Not registered yet? Register

x
Newbie184795 Lv1Posted Feb-07-2025 16:41
  
any idea after reviewing the screenshots?
Newbie147687 Posted Mar-04-2025 19:07
  
The issue you are facing likely stems from improper DHCP relay configuration on the Sangfor NGAF firewall. Since your Windows DHCP Server (192.168.18.101) is functioning correctly for other scopes, but clients cannot obtain IPs through the relay, you need to verify that the DHCP relay agent is properly forwarding requests.

First, ensure that the relay agent is enabled on the correct internal interface of the Sangfor NGAF and that it is correctly pointing to the Windows DHCP Server as the destination for DHCP requests. Next, check network communication by pinging 192.168.18.101 from a client machine to confirm connectivity. If the ping fails, inspect firewall rules on both Sangfor NGAF and Windows DHCP Server, ensuring that UDP ports 67 (DHCP Discover) and 68 (DHCP Offer) are open.

Additionally, on the Windows DHCP Server, open Windows Defender Firewall and ensure that rules allowing DHCP relay traffic are enabled. To further diagnose the issue, use Wireshark or tcpdump on the Windows DHCP Server to monitor incoming DHCP requests—filter by port 67 and 68 to confirm whether requests are reaching the server. If no requests are visible, then the Sangfor NGAF relay might not be functioning correctly, or there may be a routing issue preventing packets from reaching the DHCP server. If VLANs are in use, verify that the relay is enabled on the correct VLAN, and ensure routing is correctly configured to forward DHCP traffic.
fuadmahbubun Lv2Posted Mar-05-2025 08:47
  
Hi, based on your screen shoot, NGAF ip address is 192.168.18.254 and
ip DHCP Server is 192.168.10.205
make sure NGAF can ping to dhcp server and NGAF ip address has been registered as a dhcp relay in windows DHCP server. (router in scope option)

This topic contains more resources

You must log in to download or view the file. Not registered yet? Register

x

I Can Help:

Change

Moderator on This Board

43
6
2

Started Topics

Followers

Follow

1
148
3

Started Topics

Followers

Follow

873
173
94

Started Topics

Followers

Follow

Board Leaders