> Source: [sk133992](https://support.checkpoint.com/results/sk/sk133992)

# sk133992 - DHCP reply traffic is dropped due to 'dhcp_reply_code' when using New DHCP objects

| Property | Value |
|----------|-------|
| Solution ID | sk133992 |
| Date Created | 2018-08-20 |
| Last Modified | 2024-11-03 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82, R81.20, R81.10 (EOS), R81 (EOS) |
| OS | Gaia |

## Symptoms

- * DHCP reply traffic is dropped on an 'Accept' rule which is using the DHCP Service object `dhcp-reply` object.

* Kernel debug (`# fw ctl zdebug -m fw + drop`) is showing:

  `dropped by fw_conn_post_inspect Reason: Handler 'dhcp_reply_code' drop`
* Traffic capture shows only DHCP Offers. It does not show the corresponding DHCP Requests.

## Cause

1. DHCP request is not seen by the Security Gateway, but the DHCP reply does reach the gateway, as it is routed directly to the DHCP server.
2. The DHCP Server is not legacy (is working as non-standard)

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
