pjhtech Tools
MikroTik

MikroTik DHCP Relay Uses the Wrong Source IP

Use local-address-as-src-ip on RouterOS 7.17+ when the DHCP server path expects the relay address instead of the transit source.

If the DHCP server or its firewall expects the relay’s local-address as the packet source but receives a transit address, set local-address-as-src-ip=yes on that relay. RouterOS 7.17+ supports this for relayed Discover/Request packets; local-address still supplies the DHCP giaddr.

Use the source-address option when that is the mismatch

Read /ip/dhcp-relay/print detail. Confirm the existing relay’s local-address is the client-side relay address and the name uniquely identifies it. Replace example-relay with that name:

Configuration change • replace example-relay; requires RouterOS 7.17+
/ip/dhcp-relay/set [find where name="example-relay"] local-address-as-src-ip=yes

Scope: RouterOS IPv4 DHCP relay. The source-IP option requires RouterOS 7.17 or later.

Confirm the source mismatch when the server-side capture is unclear

Read-only
/ip/dhcp-relay/print detail
/ip/address/print
/ip/vrf/print detail
/ip/route/print detail

In the relay entry check interface, local-address, dhcp-server and dhcp-server-vrf. Find 192.0.2.1 on the client-facing interface in the address list. For this example the relay uses main and the server is 198.51.100.10; check the active route covering that address. A non-main server VRF requires that route in its own routing table.

Capture a fresh client lease exchange. First run /tool/sniffer/print; do not replace an active capture, and retain the old settings. In this example ether1 faces the server. Set the filter explicitly so an old address or MAC filter cannot silently exclude DHCP:

Temporary capture • use the actual server-facing interface
/tool/sniffer/set filter-interface=ether1 filter-direction=any filter-ip-protocol=udp filter-port=67,68 filter-ip-address="" filter-src-ip-address="" filter-dst-ip-address="" filter-ipv6-address="" filter-src-ipv6-address="" filter-dst-ipv6-address=""
/tool/sniffer/set filter-mac-address="" filter-src-mac-address="" filter-dst-mac-address="" filter-mac-protocol="" filter-src-port="" filter-dst-port=""
/tool/sniffer/set filter-vlan="" filter-cpu="" filter-size="" filter-operator-between-entries=and only-headers=no file-name=relay-check.pcap file-limit=1MiB streaming-enabled=no
/tool/sniffer/start

If starting the capture returns failure: not allowed by device-mode, follow the sniffer permission and physical-confirmation procedure before retrying.

Force a new lease on one test client. For example, in a Windows administrator terminal, run ipconfig /release "Ethernet" and then ipconfig /renew "Ethernet", using the actual adapter name. This briefly disconnects that client; keep router management on another connection. Stop the capture immediately after the attempt:

Stop capture
/tool/sniffer/stop

Download relay-check.pcap from WinBox Files and open it in Wireshark. Expand Internet Protocol for Source/Destination and Dynamic Host Configuration Protocol for Transaction ID, Relay agent IP address (giaddr), and Option 53 message type. Match the client transaction in Discover/Request and Offer/ACK. Restore the saved sniffer settings afterward. Captures contain client identifiers; keep the file private.

If the server-facing reply exists but the client never receives it, repeat on the relay’s client interface with a different file name. An empty router capture is inconclusive for traffic that bypasses the CPU; use a capture on the DHCP server or a switch mirror when needed.

If the server receives the request but sends no Offer, correct its scope, pool or server policy instead. If an Offer is sent but cannot return to giaddr, correct that return route or filter; changing the request source does not supply a missing route.

Verify a fresh lease and renewal

Check the changed IP source and unchanged giaddr in another capture. On the Windows client, ipconfig /all shows IPv4 Address, Default Gateway, DHCP Server and DNS Servers. Test renewal without releasing the lease as well as initial allocation; a renewal can go directly to the DHCP server and therefore use a different path from the initial relayed broadcast. To undo the source change, restore the previous value on the same relay; clearing all leases is unnecessary.

References