- Products
- Learn
- Local User Groups
- Partners
- More
Policy Insights and Policy Auditor in Action
19 November @ 5pm CET / 11am ET
Access Control and Threat Prevention Best Practices
Watch HereOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hey guys,
Just wondering if there might be something simple missing for office mode failing with dhcp server method ip allocation. We even replicated this in the lab (on R82 mind you), though customer is on R81.20 jumbo 92.
We followed below steps, but no luck.
When we try in the lab, it simply says "Connection failed. you cannot receive office mode IP address at this time, try to connect again"
There is an sk on support site about this exact error, but all it says its fixed in certain versions, which customer is on anyway.
Any clue what might be the fix? I even verified the connection in the lab back and forth from dhcp server, tried different VIP, no joy.
Tx as always! I attached some screenshots for this as well.
Andy
Ah. Looks like there's a filter list of MAC addresses. Or the filter is enabled but no entries are in the list.
https://www.dtonias.com/configure-dhcp-server-2016-filters/
Check this and you may need to disable the filter if it's enabled.
Just working on some Fortinet SASE stuff now, will check in a bit.
Tx brother 🙂
Andy
Do you have anything in the Policies folder under the scope? Apparently more detailed filters can be configured in there. I wonder if the server is seeing the virtual MAC address of the gateway and using that for the MAC filter address.
I checked that last week, appears to be related only to Windows class.
Try adding the MAC address 50-01-00-01-00-00 to your Allow filter. That's the MAC your earlier capture screen shot showed as coming from the firewall for the unicast DHCP relay. I see you had 50-01-00-02-00-00, however. And nothing in the Deny filter, I presume? I'm just about out of ideas, tho. 🙂
If this doesn't work, can you delete everything in the Allow and Deny filters and let it ride? Or do you require filter entries?
Yep, just tried, no luck...o well, its long weekend here, so let me clear my head till Tuesday, maybe something else comes to mind! Thanks so much again for all your help.
Andy
I will definitely troubleshoot more on windows server side next week.
Since this is bugging me so much, I cant easily let it go, until its fixed in my R82 lab 🙂
Anyway, I feel like Im getting closed after making some changes for ikev2 options in global properties for remote access. Now, I dont get allocation failure error, but it tells me user is not authorized to receive OM ip, which makes no sense, since it has full eval license.
Lady from TAC was really nice, we set up call for Feb 16th at 10 am est, lets see if we can fix it. Once we do, I will make a new post with doc I put together.
Best,
Andy
In case anyone else has this problem, I ended up fixing it in my lab by having to add below route. This part is actually 100% IMPORTANT, that was sadly missing.
Andy
In Virtual IP address for DHCP server replies, enter an IP address from the sub network of the IP addresses which are designated for Office Mode usage.
Office Mode supports DHCP Relay method for IP assignment, so you can direct the DHCP server as to where to send its replies. The routing on the DHCP server and that of internal routers must be adjusted so that packets from the DHCP server to this address are routed through the Security Gateway.
For the context, my lab dhcp server is 172.16.10.199 and gw IP is 172.16.10.253
Ah, so the gateway wasn't the default route for that network? Yep, the return route makes sense!
THANKS AGAIN FOR ALL THE HELP!! 🙂
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 7 | |
| 3 | |
| 2 | |
| 2 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 |
Tue 11 Nov 2025 @ 06:00 PM (COT)
San Pedro Sula: Risk Management al Horno: ERM, TEM & Pizza NightTue 11 Nov 2025 @ 06:00 PM (COT)
San Pedro Sula: Risk Management al Horno: ERM, TEM & Pizza NightThu 13 Nov 2025 @ 10:00 AM (CET)
Cloud Architect Series - Guarding Generative AI: Next-Gen Application Security with CloudGuard WAFThu 13 Nov 2025 @ 10:00 AM (CET)
Cloud Architect Series - Guarding Generative AI: Next-Gen Application Security with CloudGuard WAFFri 14 Nov 2025 @ 10:00 AM (CET)
CheckMates Live Netherlands - Veriti, Threat Exposure ManagementWed 19 Nov 2025 @ 11:00 AM (EST)
TechTalk: Improve Your Security Posture with Threat Prevention and Policy InsightsThu 20 Nov 2025 @ 05:00 PM (CET)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - AMERThu 20 Nov 2025 @ 10:00 AM (CST)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - EMEATue 11 Nov 2025 @ 06:00 PM (COT)
San Pedro Sula: Risk Management al Horno: ERM, TEM & Pizza NightTue 11 Nov 2025 @ 06:00 PM (COT)
San Pedro Sula: Risk Management al Horno: ERM, TEM & Pizza NightAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY