Consider following config
firewall {
global-options {
apply-to-bridged-traffic {
accept-invalid {
ethernet-type arp
ethernet-type dhcp
ethernet-type 802.1q
ethernet-type 802.1ad
}
}
state-policy {
established {
action accept
}
invalid {
action reject
}
related {
action accept
}
}
}
}
interfaces {
ethernet eth2 {
mtu 1500
}
bridge br1 {
enable-vlan
member {
interface eth2 {
native-vlan 4090
}
}
vif 4090 {
address dhcp
}
}
}Currently, accept-invalid > dhcp only handles DHCP reply but not DHCP request, so interface br1.4090 can never gets an address via DHCP.
The DHCP request will still be dropped by nftables as ct state invalid.
Manually add a rule for DHCP to kernel
nft insert rule bridge vyos_filter VYOS_OUTPUT_filter ct state invalid udp sport 68 udp dport 67 counter accept
can fix the issue.
Suggested fix:
vyos-1x/python/vyos/template.py Line 707
Change 'dhcp': 'udp sport 67 udp dport 68', to 'dhcp': 'udp sport { 67, 68 } udp dport { 67, 68 }',
or
separate dhcp into dhcp-request and dhcp-reply in firewall > global-options > apply-to-bridged-traffic > accept-invalid