> Source: [sk184688](https://support.checkpoint.com/results/sk/sk184688)

# sk184688 - DHCP clients fail to obtain an IP address from the DHCP Server on the Security Gateway after it was upgraded to R82 or higher

| Property | Value |
|----------|-------|
| Solution ID | sk184688 |
| Date Created | 2026-02-18 |
| Last Modified | 2026-02-19 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82 |
| OS | Gaia |

## Symptoms

- * Some DHCP clients intermittently or consistently fail to obtain an IP address in this scenario:

  1. DHCP Server is enabled and configured on a Check Point Security Gateway

  2. This Security Gateway was upgraded to R82 or higher

* The DHCP handshake may stop after the "DISCOVER/OFFER" phase, and the DHCP client does not proceed to the "REQUEST/ACK" phase.

* Packet capture shows the DHCP Server is sending the DHCP "OFFER" as unicast traffic instead of broadcast traffic.

## Cause

In the R82 release, the DHCP server daemon version was upgraded from 3.0.5 to 4.2.5.

As part of this change, the DHCP server implementation follows [RFC 2131](https://www.rfc-editor.org/search/rfc_search_detail.php?rfc=rfc2131) more strictly:

If the broadcast bit in the DHCP "DISCOVER" packet is not set, then then DHCP server sends the DHCP "OFFER" as unicast traffic (instead of broadcast traffic).

In environments where intermediate network devices / access-control mechanisms (for example, wireless guest networks, captive portals, or ACL-based enforcement) permit broadcast DHCP implicitly, but do not permit unicast DHCP unless explicitly allowed, the DHCP unicast traffic (UDP ports 67/68) may be blocked, preventing the DHCP client from completing a DHCP handshake.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
