Thank you for this info KPeetermans. The issue with multiple DHCP servers might be the case here, with an ISP using a possible large broadcast network. This connection works OK with a Juniper though, but I will check the DHCP traffic as suggested. KPeetermans wrote: Do you happen to be on a network segment that 'sees' multiple dhcp-servers ? There is a bug in the 4.1.x version where the PA will send it's DHCP renewal to the last DHCP server it sees on the 'broadcast segment', which may not be the correct dhcp server. For example, I experience this problem on the segment behind my cable modem, and when there is a DHCP renewal seen from my Digital TV recorder just before the PA needs to renew, the PA sends the DHCP renewal to this (private) IP address, which doesn't work for renewing it's own IP address. You could try to sniff all DHCP traffic on your interface, and check if the PA sends the renewal to the correct DHCP server. That's how I found the issue. My ticket has been open for more than 2 months now, but from what I've heard this is already fixed for upcoming version 5.0 and will probably get backported to some 4.1.x version
... View more