Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Reject WAN DHCP Subnet from cable modem

    Scheduled Pinned Locked Moved DHCP and DNS
    6 Posts 4 Posters 2.9k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • R Offline
      Reseau360
      last edited by

      Hi guys,

      [sorry for my english, it's my second language]

      Second post regarding problems with my ISP Cable Modem.

      In the beginning of July, i started having problems with WAN DHCP adresses.

      Each week, pfSense was going Offline after it failed to renew => DHCP WAN address

      I tried to configure the WAN Interface => reject subnet DHCP address => 192.168.100.X/24

      Also tried to add => rules => block => WAN => IPv4 => UDP => source => any => destination => any => port 67/68

      After 2 weeks trying to fix this, i decided to switch back to my Watchguard XTM-26 and the problem disappeared.

      This week, i had to install a new business network environment, so i decided to test again, but same problems again, haven't figured out what the hell is going on.

      So i've setup a VMWare environment to test further.

      I'm trying to reject DHCP WAN subnet => 192.168.1.X/24 => doesn't seem to work => still having an address from 192.168.1.0/24, when i'm not supposed to.

      I guess i''m missing something here, any inputs would be appreciated regarding Cable Modem WAN DHCP addresses. [trying to reject bad WAN DHCP address]

      Thanks guys.

      1 Reply Last reply Reply Quote 0
      • johnpozJ Offline
        johnpoz LAYER 8 Global Moderator
        last edited by

        so when you set an interface to be dhcp, pfsense auto puts in rule to allow dhcp which would before any rules you create in gui.  So no your firewall rule would never work.

        Only time cable modem would hand out 192.168.100 is if has no wan connection.  As to blocking this.. Post up what you did.

        So I would suggest you sniff on the your wan watch the dhcp packets..  The reject is the IP address or network of the dhcp server, not the IP in the scope.  Is quite possible then when your cable modem hands out dhcp for 192.168.100 that is using a different source IP?

        An intelligent man is sometimes forced to be drunk to spend time with his fools
        If you get confused: Listen to the Music Play
        Please don't Chat/PM me for help, unless mod related
        SG-4860 25.07.1 | Lab VMs 2.8.1, 25.07.1

        1 Reply Last reply Reply Quote 0
        • stan-qazS Offline
          stan-qaz
          last edited by

          Try going to the Interfaces, WAN page and set it to reject the cable modem's internal IP address there.

          http://172.16.0.1/interfaces.php?if=wan  (use your pfSense's IP here)

          Reject leases from 
          
          192.168.100.1
          
          If there is a certain upstream DHCP server that should be ignored, place the IP address or subnet of the DHCP server to be ignored here. This is useful for rejecting leases from cable modems that offer private IPs when they lose upstream sync.
          
          1 Reply Last reply Reply Quote 0
          • R Offline
            Reseau360
            last edited by

            Ok,

            I've tried the above solution, but it doesn't seem to work.

            Here's my setup

            Internal Lab Network - Windows Server 2012 R2 - DHCP Subnet - 10.X.X.X/24 [Range 10.X.X-50 to 75] ========> pfSense WAN DHCP Rejecting 10.X.X.52 ==========> LAN VMNet Host Only 10.12.12.X/24

            Even if i try to reject => 10.X.X.52 …... I still get the IP Address i'm trying to reject !

            Am I missing something here ?

            Print Screen attached

            WAN_DHCP_Reject_1.PNG
            WAN_DHCP_Reject_1.PNG_thumb

            1 Reply Last reply Reply Quote 0
            • DerelictD Offline
              Derelict LAYER 8 Netgate
              last edited by

              You reject from the DHCP Server IP address. What is the IP address of the DHCP Server? Put that there.

              The purpose of that setting is to refuse leases offered by cable modems when the connection is down. When the connection is up the DHCP server offering the lease will not be the cable modem, but something upstream of it.

              Chattanooga, Tennessee, USA
              A comprehensive network diagram is worth 10,000 words and 15 conference calls.
              DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
              Do Not Chat For Help! NO_WAN_EGRESS(TM)

              1 Reply Last reply Reply Quote 0
              • R Offline
                Reseau360
                last edited by

                So here's more details regarding my test lab [i've put the wrong IP Addresses but the configuration remain the same]

                Cable Modem ===> Firewall ===> Switch L3 ===> VMWare Esxi ===> Nothing here that can offer IP Addresses, nothing upstream either ==== > W2012R2 - Static IP : 10.115.115.254/24 DHCP Server Range 10.115.115.50 to 75 ===> WAN pfSense ===> LAN pfSense VM Host-only 10.12.12.X/24 ===> Windows 7 VM

                So, even if i put the DHCP Server Address 10.115.115.254, i still get an IP Address from 10.115.115.50 to 75.

                There's nothing upstream, so it simulate the problem i was having.

                If my ISP doesn't offer an IP Address or goes offline, my cable modem should kick in and offer me => 192.168.100.X .

                So basicaly in my test lab, if i've configure to reject an IP Address from the DHCP server, i shouldn't get an IP Address at all, so i shouldn't get an IP Address from 10.115.115.50 to 75 …..  right ?

                1 Reply Last reply Reply Quote 0
                • First post
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.