Page MenuHomeVyOS Platform

Failed to obtain IP via DHCP on VLAN aware bridge.
Open, NormalPublicBUG

Description

Consider following config

firewall {
  global-options {
     apply-to-bridged-traffic {
         accept-invalid {
             ethernet-type arp
             ethernet-type dhcp
             ethernet-type 802.1q
             ethernet-type 802.1ad
         }
     }
     state-policy {
         established {
             action accept
         }
         invalid {
             action reject
         }
         related {
             action accept
         }
     }
  }
}
interfaces {
  ethernet eth2 {
    mtu 1500
  }
  bridge br1 {
     enable-vlan
     member {
         interface eth2 {
             native-vlan 4090
         }
     }
     vif 4090 {
         address dhcp
     }
  }
}

Currently, accept-invalid > dhcp only handles DHCP reply but not DHCP request, so interface br1.4090 can never gets an address via DHCP.
The DHCP request will still be dropped by nftables as ct state invalid.

Manually add a rule for DHCP to kernel

nft insert rule bridge vyos_filter VYOS_OUTPUT_filter ct state invalid udp sport 68 udp dport 67 counter accept

can fix the issue.

Suggested fix:

vyos-1x/python/vyos/template.py Line 707

Change 'dhcp': 'udp sport 67 udp dport 68', to 'dhcp': 'udp sport { 67, 68 } udp dport { 67, 68 }',

or

separate dhcp into dhcp-request and dhcp-reply in firewall > global-options > apply-to-bridged-traffic > accept-invalid

Details

Version
VyOS 1.5-rolling-202607291208
Is it a breaking change?
Behavior change
Issue type
Bug (incorrect behavior)