<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic DHCP Relay with Source Nat blocked in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/dhcp-relay-with-source-nat-blocked/m-p/309167#M80146</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;a customer has two PA VMs in the Azure cloud with internal loadbalancers configured. Unfortunately the DHCP server is also running there. In order to perform symmetric return a source nat is needed on the firewall. However this breaks the DHCP flow between DHCP relay and windows DHCP server. The DHCP server always replies to the relay agent (switch or on-premise firewall) address instead of the source IP which is the firewall ip. When the DHCP server sends the DHCP Offer message back to the relay agent address the packet is blocked, which is also described in this knowledge article:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClZUCA0" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClZUCA0&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My question is why it is blocking the DHCP Offer, the protocol is UDP and shouldn't the firewall just see it as a new session?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 03 Feb 2020 15:33:52 GMT</pubDate>
    <dc:creator>JuergenHolzer</dc:creator>
    <dc:date>2020-02-03T15:33:52Z</dc:date>
    <item>
      <title>DHCP Relay with Source Nat blocked</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dhcp-relay-with-source-nat-blocked/m-p/309167#M80146</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;a customer has two PA VMs in the Azure cloud with internal loadbalancers configured. Unfortunately the DHCP server is also running there. In order to perform symmetric return a source nat is needed on the firewall. However this breaks the DHCP flow between DHCP relay and windows DHCP server. The DHCP server always replies to the relay agent (switch or on-premise firewall) address instead of the source IP which is the firewall ip. When the DHCP server sends the DHCP Offer message back to the relay agent address the packet is blocked, which is also described in this knowledge article:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClZUCA0" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClZUCA0&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My question is why it is blocking the DHCP Offer, the protocol is UDP and shouldn't the firewall just see it as a new session?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Feb 2020 15:33:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dhcp-relay-with-source-nat-blocked/m-p/309167#M80146</guid>
      <dc:creator>JuergenHolzer</dc:creator>
      <dc:date>2020-02-03T15:33:52Z</dc:date>
    </item>
    <item>
      <title>Re: DHCP Relay with Source Nat blocked</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dhcp-relay-with-source-nat-blocked/m-p/309219#M80153</link>
      <description>&lt;P&gt;It's hard to pinpoint the issue without details, but the article says as below.&lt;BR /&gt;&lt;EM&gt;"This incorrect flow was dropped by the firewall, which caused the end hosts to not receive the IP address because the DHCP Offer never reached the DHCP relay device."&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1) I recommend you to check the network reachability.&lt;BR /&gt;2) Check the firewall rules.&lt;BR /&gt;3) You may use the following CLI commands if the packets are dropping, or do a packet capture on the firewall.&lt;/P&gt;&lt;P&gt;&amp;gt; show counter global filter severity drop&lt;BR /&gt;&amp;gt; show counter global filter delta yes severity drop&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope this helps,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 03 Feb 2020 18:32:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dhcp-relay-with-source-nat-blocked/m-p/309219#M80153</guid>
      <dc:creator>AnalysisMan</dc:creator>
      <dc:date>2020-02-03T18:32:59Z</dc:date>
    </item>
  </channel>
</rss>

