Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    DHCP not working on second interface

    Scheduled Pinned Locked Moved DHCP and DNS
    17 Posts 5 Posters 2.5k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S
      sam_maher
      last edited by

      We have been trying to setup captive portal. It wasn't working so we have gone back to basics and found the DHCP isn't working on the interface.

      I have an allow all rule in on the firewall for the correct interface and have check the other settings e.g DHCP is enabled, The range is correct and still no luck.

      There is nothing relevant showing the DHCP logs.

      If i set a static IP on my machine it all works as it should be.

      Some advice would be greatly appreciated

      Thanks

      1 Reply Last reply Reply Quote 0
      • KOMK
        KOM
        last edited by

        Do you have DHCP specifically enabled for that interface?  Post your DHCP settings for the interface in question, as well as the firewall rules for it.

        You could always sniff the traffic and see if the DHCP handshaking is happening, and which side isn't responding.

        1 Reply Last reply Reply Quote 0
        • S
          sam_maher
          last edited by

          Thanks for the speedy reply, Yes DHCP is enabled for that interface.

          Please see attached for the settings

          Edit: Here is the output for wireshark. Looks like pfsense isnt responding

          dhcp.png
          dhcp.png_thumb
          Firewall.png
          Firewall.png_thumb
          ![Screenshot (1).png](/public/imported_attachments/1/Screenshot (1).png)
          ![Screenshot (1).png_thumb](/public/imported_attachments/1/Screenshot (1).png_thumb)

          1 Reply Last reply Reply Quote 0
          • KOMK
            KOM
            last edited by

            Looks good so far.  What do you get if you capture on pfSense OPT1?  Does it see the request?

            1 Reply Last reply Reply Quote 0
            • S
              sam_maher
              last edited by

              This is what i got from PFSense

              ![Screenshot (2).png](/public/imported_attachments/1/Screenshot (2).png)
              ![Screenshot (2).png_thumb](/public/imported_attachments/1/Screenshot (2).png_thumb)

              1 Reply Last reply Reply Quote 0
              • DerelictD
                Derelict LAYER 8 Netgate
                last edited by

                That looks like the interface on the client.

                On your router do a Diagnostics > Packet Capture on OPT2 and try to get a DHCP lease again.

                Chattanooga, Tennessee, USA
                A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                Do Not Chat For Help! NO_WAN_EGRESS(TM)

                1 Reply Last reply Reply Quote 0
                • S
                  sam_maher
                  last edited by

                  That was the packet capture from PFSense, Ive imported it into wireshark

                  Sam

                  1 Reply Last reply Reply Quote 0
                  • DerelictD
                    Derelict LAYER 8 Netgate
                    last edited by

                    Stop and restart the DHCP service or reboot I guess.

                    Chattanooga, Tennessee, USA
                    A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                    DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                    Do Not Chat For Help! NO_WAN_EGRESS(TM)

                    1 Reply Last reply Reply Quote 0
                    • S
                      sam_maher
                      last edited by

                      Have tried that, No luck :(

                      1 Reply Last reply Reply Quote 0
                      • DerelictD
                        Derelict LAYER 8 Netgate
                        last edited by

                        Anything in the advanced config of the DHCP server?

                        Chattanooga, Tennessee, USA
                        A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                        DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                        Do Not Chat For Help! NO_WAN_EGRESS(TM)

                        1 Reply Last reply Reply Quote 0
                        • KOMK
                          KOM
                          last edited by

                          … or the general System log?

                          1 Reply Last reply Reply Quote 0
                          • S
                            sam_maher
                            last edited by

                            No there is nothing in the advanced config and here is what i have found in the log:

                            Oct 8 09:16:01 php-fpm[33740]: /rc.newwanip: The command '/usr/local/sbin/dhcpd -user dhcpd -group _dhcp -chroot /var/dhcpd -cf /etc/dhcpd.conf -pf /var/run/dhcpd.pid igb1 igb0' returned exit code '1', the output was 'Internet Systems Consortium DHCP Server 4.2.8 Copyright 2004-2015 Internet Systems Consortium. All rights reserved. For info, please visit https://www.isc.org/software/dhcp/ Wrote 99 leases to leases file. Listening on BPF/igb0/a0:36:9f:22:4a:48/192.168.26.0/24 Sending on BPF/igb0/a0:36:9f:22:4a:48/192.168.26.0/24 Listening on BPF/igb1/a0:36:9f:22:4a:49/192.168.0.0/24 Sending on BPF/igb1/a0:36:9f:22:4a:49/192.168.0.0/24 Can't bind to dhcp address: Address already in use Please make sure there is no other dhcp server running and that there's no entry for dhcp or bootp in /etc/inetd.conf. Also make sure you are not running HP JetAdmin software, which includes a bootp server. If you did not get this software from ftp.isc.org, please get the latest from ftp.isc.org and install that befor

                            1 Reply Last reply Reply Quote 0
                            • johnpozJ
                              johnpoz LAYER 8 Global Moderator
                              last edited by

                              Well seems you got something listening on that interface and you can not bind to it..

                              Listening on BPF/igb1/a0:36:9f:22:4a:49/192.168.0.0/24
                              Sending on BPF/igb1/a0:36:9f:22:4a:49/192.168.0.0/24 Can't bind to dhcp address: Address already in use

                              An intelligent man is sometimes forced to be drunk to spend time with his fools
                              If you get confused: Listen to the Music Play
                              Please don't Chat/PM me for help, unless mod related
                              SG-4860 24.11 | Lab VMs 2.8, 24.11

                              1 Reply Last reply Reply Quote 0
                              • S
                                sam_maher
                                last edited by

                                Thats what i thought, Im trying to bind to "igb0".  "igb1" is the current LAN which works fine.

                                I have tried restarting DHCP and changing the IP range with no luck.

                                1 Reply Last reply Reply Quote 0
                                • DerelictD
                                  Derelict LAYER 8 Netgate
                                  last edited by

                                  DHCP Relay somehow enabled on that interface?

                                  See if you somehow you got past the GUI logic.  Disable all your DHCP servers and see if DHCP Relay is enabled?  Just a guess.

                                  Chattanooga, Tennessee, USA
                                  A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                                  DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                                  Do Not Chat For Help! NO_WAN_EGRESS(TM)

                                  1 Reply Last reply Reply Quote 0
                                  • S
                                    sam_maher
                                    last edited by

                                    Just checked and the dhcp relay was not enabled.

                                    1 Reply Last reply Reply Quote 0
                                    • C
                                      cmb
                                      last edited by

                                      Check the output of 'sockstat -4', it'll show you which process is bound to that port already.

                                      1 Reply Last reply Reply Quote 0
                                      • First post
                                        Last post
                                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.