Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    HELP! Seemingly bizarre dhclient behavior on WAN

    2.4 Development Snapshots
    9
    29
    6.1k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • jimpJ
      jimp Rebel Alliance Developer Netgate
      last edited by

      Yep, it's common cable modem behavior. My modem, an older Motorola Surfboard, does this with that exact address. It's the reason I added that GUI field years ago.

      Remember: Upvote with the šŸ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

      Need help fast? Netgate Global Support!

      Do not Chat/PM for help!

      1 Reply Last reply Reply Quote 0
      • P
        Phil.Scarr
        last edited by

        @jimp:

        Yep, it's common cable modem behavior. My modem, an older Motorola Surfboard, does this with that exact address. It's the reason I added that GUI field years ago.

        So it just did it again and the recovery time was much quicker, about 30 seconds instead of 2 minutes.Ā  But I still want to know what's going on.Ā  I guess I should call Charter and get them to test my line again.Ā  My CM shouldn't be losing sync like this, a couple of times a day.

        1 Reply Last reply Reply Quote 0
        • jimpJ
          jimp Rebel Alliance Developer Netgate
          last edited by

          Usually it's indicative of an upstream issue. Mine only does that when the upstream sync is lost.

          Remember: Upvote with the šŸ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

          Need help fast? Netgate Global Support!

          Do not Chat/PM for help!

          1 Reply Last reply Reply Quote 0
          • luckman212L
            luckman212 LAYER 8
            last edited by

            Wish there was a way to blanket reject any lease coming from an rfc1918 address but I checked the source code for dhclient and it looks like it only accepts individual IPs right now.

            1 Reply Last reply Reply Quote 0
            • P
              Phil.Scarr
              last edited by

              @luckman212:

              Wish there was a way to blanket reject any lease coming from an rfc1918 address but I checked the source code for dhclient and it looks like it only accepts individual IPs right now.

              Will it take multiple IPs?Ā  So if for some strange reason there are 3 DHCP servers reachable but only 1 is real, can I put in a comma-separated list?

              1 Reply Last reply Reply Quote 0
              • luckman212L
                luckman212 LAYER 8
                last edited by

                @Phil.Scarr:

                Will it take multiple IPs?

                I am not sure- try it and then take a look at your /var/etc/dhclient_XXX.conf (for whichever wan) file to see if the config was written correctly.

                1 Reply Last reply Reply Quote 0
                • ?
                  A Former User
                  last edited by

                  I do not know if your cable modem can be put into bridge mode but it is worth finding out. You may lose wireless but ideally you want everything behind pfsense anyway. If the modem is creating a problem just bridge right through it. Speed could see increase also.

                  1 Reply Last reply Reply Quote 0
                  • P
                    Phil.Scarr
                    last edited by

                    @webtyro:

                    I do not know if your cable modem can be put into bridge mode but it is worth finding out. You may lose wireless but ideally you want everything behind pfsense anyway. If the modem is creating a problem just bridge right through it. Speed could see increase also.

                    I assume that that would be something the cable company would have to do, right?Ā  I don't have wireless on my CM, I have an access point on my LAN.

                    1 Reply Last reply Reply Quote 0
                    • P
                      Phil.Scarr
                      last edited by

                      @webtyro:

                      I do not know if your cable modem can be put into bridge mode but it is worth finding out. You may lose wireless but ideally you want everything behind pfsense anyway. If the modem is creating a problem just bridge right through it. Speed could see increase also.

                      Oh, apparently not…  http://fascinated.fm/post/2379188731/getting-a-motorola-sbg6580-into-bridge-mode-on

                      Getting a Motorola SBG6580 into ā€œBridgeā€ mode on TimeWarner Wideband

                      • Unplug coax cable from Motorola

                      • Hold down the white reset button on the back panel with a pen for 30s.Ā  This resets all settings to factory defaults. The modem will be auto-reconfigured once you plug in the coax cable.

                      • When modem is back on plug in a computer with an Ethernet cable into the modem.

                      • Connect to http://192.168.0.1 and login with ā€œadminā€ / ā€œmotorolaā€

                      • Now you will make some changes:

                      • Wireless -> Primary Network -> Disabled

                      • Basic -> Setup -> NAPT Mode -> Disabled

                      • Basic -> DHCP -> No

                      • Advanced -> Options -> Rg Passthrough -> Enable

                      • Advanced -> Options -> Passthrough Mac Addresses -> Add WAN MAC address of your router 6. Connect port 1 on the Motorola modem to the WAN port of your router.

                      1 Reply Last reply Reply Quote 0
                      • jimpJ
                        jimp Rebel Alliance Developer Netgate
                        last edited by

                        Doesn't matter. Even in bridge mode it hands that out when it loses upstream sync

                        Remember: Upvote with the šŸ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

                        Need help fast? Netgate Global Support!

                        Do not Chat/PM for help!

                        1 Reply Last reply Reply Quote 0
                        • ?
                          A Former User
                          last edited by

                          @jimp:

                          Doesn't matter. Even in bridge mode it hands that out when it loses upstream sync

                          His log shows the DHCP attempt from the modem with the private address seems to me is possible causing the sync issue. Does it to you. I know my setup here using a bridged Actiontec is rock solid.
                          I have to shut everything down overnight just to receive a new gateway. Sync may not be an issue with the modem out of DHCP service. What do you think. Worth a shot?

                          1 Reply Last reply Reply Quote 0
                          • jimpJ
                            jimp Rebel Alliance Developer Netgate
                            last edited by

                            That's just how these Moto Surfboard/Arris modems work. They bridge when they have sync and when they don't have sync they hand out a private address. Presumably so you can hit the modem and troubleshoot.

                            Remember: Upvote with the šŸ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

                            Need help fast? Netgate Global Support!

                            Do not Chat/PM for help!

                            1 Reply Last reply Reply Quote 0
                            • ?
                              A Former User
                              last edited by

                              @jimp:

                              That's just how these Moto Surfboard/Arris modems work. They bridge when they have sync and when they don't have sync they hand out a private address. Presumably so you can hit the modem and troubleshoot.

                              Bridge mode with a mind of its own. Pffft. Figures! Reset button be damned.

                              1 Reply Last reply Reply Quote 0
                              • P
                                Phil.Scarr
                                last edited by

                                @jimp:

                                That's just how these Moto Surfboard/Arris modems work. They bridge when they have sync and when they don't have sync they hand out a private address. Presumably so you can hit the modem and troubleshoot.

                                From my limited research into this, there does seem to be a way to force the modem to stay in bridge mode all the time, whether it has sync or not…  But I haven't tried to set it up yet.

                                http://fascinated.fm/post/2379188731/getting-a-motorola-sbg6580-into-bridge-mode-on

                                1 Reply Last reply Reply Quote 0
                                • A
                                  athurdent
                                  last edited by

                                  Nowadays cable providers tend to force the modem configuration on the device. It's most likely that all your local config modifications disappear at some point, at least after a reboot.
                                  Back in the days you could simply upload a different config file and the device would do 100 MBit insted of the 10 you payed for. The providers did not like this as much as the customers did, so… :)
                                  Just be glad that you still have a modem with bridge mode. Most of the providers here in Germany disable bridge mode completely.

                                  1 Reply Last reply Reply Quote 0
                                  • ?
                                    A Former User
                                    last edited by

                                    @athurdent
                                    Where I am the ISP has a newer modem with bridge mode available but the older one I have they tried to hide the setting with CSS trickery. Reboots are no problem but if the ISP was still updating the firmware then you would lose your setting. Mine is just old enough they have not bothered with any firmware upgrades. Been solid for couple of years now. For this model I just use Firefox in Developer mode and change the CSS setting that hides the bridge mode checkbox, then quickly save my change.
                                    This is tricky because the browser refresh will put you back to square one so getting the CSS changed and saving my setting is under a time limit. Took a few attempts.
                                    If you are lucky maybe they are just hiding it from you.Ā 
                                    Some models have pages with no link to hide it.;)

                                    1 Reply Last reply Reply Quote 0
                                    • H
                                      ha11oga11o
                                      last edited by

                                      Hello all,

                                      sory for bumping topic, but i really need to know is there possible to add multiple IPs to make the DHCP client reject leases from an undesirable DHCP server. Seems my isp has 5 or 6 different IPs now. Ihave nasty issues with Dynamic dns not been able to resolve public IP etc. Various problems ppls connecting to my gaming sessions. Slow response of PfSense GUI due checking hostname ip and such. Just please tell me how to add Ips.

                                      Many thnx in advance.

                                      1 Reply Last reply Reply Quote 0
                                      • jimpJ
                                        jimp Rebel Alliance Developer Netgate
                                        last edited by

                                        No, the client can only ignore one address.

                                        Remember: Upvote with the šŸ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

                                        Need help fast? Netgate Global Support!

                                        Do not Chat/PM for help!

                                        1 Reply Last reply Reply Quote 0
                                        • luckman212L
                                          luckman212 LAYER 8
                                          last edited by

                                          I admit my C skills are questionable, but I was looking at the source code of dhclient and it appears that a comma-delimited list of multiple ignore IPs would actually be valid here.

                                          see: L945 of dhclient/clparse.c

                                          If you guys agree that would be acceptable, I can make a patch & submit a pull request.

                                          1 Reply Last reply Reply Quote 0
                                          • jimpJ
                                            jimp Rebel Alliance Developer Netgate
                                            last edited by

                                            Give it a try and see if it works. The man page only claims a single address:

                                            Ā  Ā   reject ip-address;
                                            Ā  Ā  Ā  Ā  Ā  Ā   The reject statement causes the DHCP client to reject offers from
                                            Ā  Ā  Ā  Ā  Ā  Ā   servers who use the specified address as a server identifier.
                                            Ā  Ā  Ā  Ā  Ā  Ā   This can be used to avoid being configured by rogue or
                                            Ā  Ā  Ā  Ā  Ā  Ā   misconfigured DHCP servers, although it should be a last resort -
                                            Ā  Ā  Ā  Ā  Ā  Ā   better to track down the bad DHCP server and fix it.
                                            

                                            Remember: Upvote with the šŸ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

                                            Need help fast? Netgate Global Support!

                                            Do not Chat/PM for help!

                                            1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.