[Kea-users] Relayed DHCP packets fail

Brian Mulder brian.mulder42 at gmail.com
Sat Nov 11 00:13:04 UTC 2023


Today I tried updating my firewall (pfSense) to the newest version (from
23.05.1 to 23.09). While the update was successful, all client DHCP
requests began to fail. I use DHCP relay on the firewall to handle DHCP on
multiple VLANs, which had been working flawlessly for multiple years.

After some trouble shooting and packet comparisons, the only difference
that I noticed was that the source port in the egress DHCP relay packet was
static 67 in the previous version and random in the new update. Reverting
the update fixed the issue.

A search indicated that RFC 8357 allows the source port to be generalized
for DHCP relay. I am using version 2.0.3 of Kea, which is a little old now.
I will try to upgrade during an upcoming downtime window.

In the meantime, what version of Kea implements RFC 8357?
Until I can upgrade, are there any configuration options in 2.0.3 to handle
relayed DHCP requests from ports other than 67?

Best regards,
Ben Monroe
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.isc.org/pipermail/kea-users/attachments/20231111/326789af/attachment.htm>


More information about the Kea-users mailing list