Page MenuHomeVyOS Platform

DHCP HA breaks after upgrading from 1.4 to 1.5 version
Closed, WontfixPublicBUG

Description

DHCP HA communication fails after upgrading the device from 1.4.4 version to the Stream release 2026.02. In 1.4 ISC DHCP, the high-availability option name accepts a descriptive name and expects the same value to be defined on both primary and secondary DHCP servers.

Whereas in 1.5, the KEA DHCP server expects the peer’s hostname to be defined in the option "name" for successful high-availability communication, which is picked from the section define in /run/kea/kea-dhcp4.conf file

:

"parameters": {
              "high-availability": [{"this-server-name": "dhcp-server01", "mode": "hot-standby", "heartbeat-delay": 10000, "max-response-delay": 10000, "max-ack-delay": 5000, "max-unacked-clients": 0, "peers": [{"name": "dhcp-server01", "url": "http://192.168.12.2:647/", "role": "primary", "auto-failover": true}, {"name": "dhcp-server02", "url": "http://192.168.12.3:647/", "role": "standby", "auto-failover": true}]}]

Primary dhcp server:

set service dhcp-server high-availability name 'dhcp-server02'

https://docs.vyos.io/en/latest/configuration/service/dhcp-server.html#example

Error after upgrading from 1.4 to 1.5 version:

Mar 17 11:44:31 kea-dhcp4[2200]: 2026-03-17 11:44:31.097 INFO  [kea-dhcp4.commands/2200.139911089342144] COMMAND_RECEIVED Received command 'ha-heartbeat'
Mar 17 11:44:37 kea-dhcp4[2200]: 2026-03-17 11:44:37.856 WARN  [kea-dhcp4.ha-hooks/2200.139911097734848] HA_HEARTBEAT_FAILED dhcp-server01: heartbeat to dhcp-server02 (http://192.168.12.3:647/) failed: dhcp-server01 matches no configured 'server-name' (error code 1)
Mar 17 11:44:37 kea-dhcp4[2200]: 2026-03-17 11:44:37.857 WARN  [kea-dhcp4.ha-hooks/2200.139911097734848] HA_COMMUNICATION_INTERRUPTED dhcp-server01: communication with dhcp-server02 is interrupted
Mar 17 11:44:41 kea-dhcp4[2200]: 2026-03-17 11:44:41.108 INFO  [kea-dhcp4.commands/2200.139911089342144] COMMAND_RECEIVED Received command 'ha-heartbeat'
Mar 17 11:44:47 kea-dhcp4[2200]: 2026-03-17 11:44:47.869 WARN  [kea-dhcp4.ha-hooks/2200.139911097734848] HA_HEARTBEAT_FAILED dhcp-server01: heartbeat to dhcp-server02 (http://192.168.12.3:647/) failed: dhcp-server01 matches no configured 'server-name' (error code 1)

Error observed in 1.4 when different names are configured:

Mar 17 11:24:36 dhcpd[3231]: Failover CONNECT to dhcp-server02 rejected: Connection rejected, invalid failover partner.
Mar 17 11:24:36 dhcpd[3231]: Failover CONNECT to dhcp-server02 rejected: Connection rejected, invalid failover partner.
Mar 17 11:24:38 dhcpd[3231]: DHCPREQUEST for 192.168.12.142 from 0c:af:0d:eb:00:00 (vyos) via eth1: not responding (recovering)
Mar 17 11:24:41 dhcpd[3231]: Failover CONNECT to dhcp-server02 rejected: Connection rejected, invalid failover partner.
Mar 17 11:24:41 dhcpd[3231]: Failover CONNECT to dhcp-server02 rejected: Connection rejected, invalid failover partner.
Mar 17 11:24:46 dhcpd[3231]: Failover CONNECT to dhcp-server02 rejected: Connection rejected, invalid failover partner.
Mar 17 11:24:46 dhcpd[3231]: Failover CONNECT to dhcp-server02 rejected: Connection rejected, invalid failover partner.
Mar 17 11:24:48 dhcpd[3231]: DHCPREQUEST for 192.168.12.142 from 0c:af:0d:eb:00:00 (vyos) via eth1: not responding (recovering)
Mar 17 11:24:51 dhcpd[3231]: Failover CONNECT to dhcp-server02 rejected: Connection rejected, invalid failover partner.
Mar 17 11:24:51 dhcpd[3231]: Failover CONNECT to dhcp-server02 rejected: Connection rejected, invalid failover partner.
Mar 17 11:24:56 dhcpd[3231]: Failover CONNECT to dhcp-server02 rejected: Connection rejected, invalid failover partner.
Mar 17 11:24:56 dhcpd[3231]: Failover CONNECT to dhcp-server02 rejected: Connection rejected, invalid failover partner.

Configuration attached.

Details

Version
1.4.4
Is it a breaking change?
Behavior change
Issue type
Bug (incorrect behavior)

Event Timeline

SrividyaA triaged this task as High priority.
dmbaturin changed Is it a breaking change? from Unspecified (possibly destroys the router) to Behavior change.
dmbaturin claimed this task.
dmbaturin subscribed.

This is an annoying problem but unfortunately there's nothing on the VyOS side we can do about it.

Since correctly configuring HA with a Kea-based implementation requires knowing the hostname of the peer, it's not possible to fix with a migration script, since a migration script only has access to the local config and doesn't have a way to retrieve any information about a remote system. And it's not feasible to change Kea to behave like ISC DHCPD, since its maintainers intentionally redesigned it that way.

People will have to adjust their configs manually for upgrade. I will include an advisory about that in the release post.