- CheckMates
- :
- Products
- :
- Quantum
- :
- Remote Access VPN
- :
- Re: Office mode DHCP method failure
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Office mode DHCP method failure
Hey guys,
Just wondering if there might be something simple missing for office mode failing with dhcp server method ip allocation. We even replicated this in the lab (on R82 mind you), though customer is on R81.20 jumbo 92.
We followed below steps, but no luck.
When we try in the lab, it simply says "Connection failed. you cannot receive office mode IP address at this time, try to connect again"
There is an sk on support site about this exact error, but all it says its fixed in certain versions, which customer is on anyway.
Any clue what might be the fix? I even verified the connection in the lab back and forth from dhcp server, tried different VIP, no joy.
Tx as always! I attached some screenshots for this as well.
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
All I keep sesing is whats attached, with few different MAC addresses, but though all are allowed, same issue.
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Ah. Looks like there's a filter list of MAC addresses. Or the filter is enabled but no entries are in the list.
https://www.dtonias.com/configure-dhcp-server-2016-filters/
Check this and you may need to disable the filter if it's enabled.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Just working on some Fortinet SASE stuff now, will check in a bit.
Tx brother 🙂
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Looks like they are all allowed.
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Do you have anything in the Policies folder under the scope? Apparently more detailed filters can be configured in there. I wonder if the server is seeing the virtual MAC address of the gateway and using that for the MAC filter address.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I checked that last week, appears to be related only to Windows class.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Try adding the MAC address 50-01-00-01-00-00 to your Allow filter. That's the MAC your earlier capture screen shot showed as coming from the firewall for the unicast DHCP relay. I see you had 50-01-00-02-00-00, however. And nothing in the Deny filter, I presume? I'm just about out of ideas, tho. 🙂
If this doesn't work, can you delete everything in the Allow and Deny filters and let it ride? Or do you require filter entries?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yep, just tried, no luck...o well, its long weekend here, so let me clear my head till Tuesday, maybe something else comes to mind! Thanks so much again for all your help.
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I will definitely troubleshoot more on windows server side next week.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Since this is bugging me so much, I cant easily let it go, until its fixed in my R82 lab 🙂
Anyway, I feel like Im getting closed after making some changes for ikev2 options in global properties for remote access. Now, I dont get allocation failure error, but it tells me user is not authorized to receive OM ip, which makes no sense, since it has full eval license.
Lady from TAC was really nice, we set up call for Feb 16th at 10 am est, lets see if we can fix it. Once we do, I will make a new post with doc I put together.
Best,
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
In case anyone else has this problem, I ended up fixing it in my lab by having to add below route. This part is actually 100% IMPORTANT, that was sadly missing.
Andy
-
In Virtual IP address for DHCP server replies, enter an IP address from the sub network of the IP addresses which are designated for Office Mode usage.
Office Mode supports DHCP Relay method for IP assignment, so you can direct the DHCP server as to where to send its replies. The routing on the DHCP server and that of internal routers must be adjusted so that packets from the DHCP server to this address are routed through the Security Gateway.
For the context, my lab dhcp server is 172.16.10.199 and gw IP is 172.16.10.253
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Ah, so the gateway wasn't the default route for that network? Yep, the return route makes sense!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
THANKS AGAIN FOR ALL THE HELP!! 🙂

- « Previous
-
- 1
- 2
- Next »