DHCP packets dropped by Cisco ACI when using NSX DHCP Relay
search cancel

DHCP packets dropped by Cisco ACI when using NSX DHCP Relay

book

Article ID: 448709

calendar_today

Updated On:

Products

VMware NSX

Issue/Introduction

  • VMware NSX virtual machines on overlay segments fail to receive DHCP IP addresses when using an external DHCP server located within a Cisco ACI fabric.

  • DHCP Discover packets reach the external DHCP server.

  • DHCP Offer packets are transmitted by the server but never reach the NSX Edges.

  • Cisco ACI leaf logs show the following error:
    relayback_response: #### : dhcp_relayback_response : option 82 not present. Drop the packet

Environment

  • VMware NSX 4.x / 9.x
  • Cisco ACI Fabric

Cause

The Cisco ACI fabric is configured with DHCP Snooping or a secondary DHCP Relay on the Bridge Domain (BD). ACI expects DHCP Option 82 (Relay Agent Information) to be present in returning unicast DHCP Offer packets. Because the NSX DHCP Relay is the first-hop relay and does not inject Option 82, ACI identifies the returning packet as malformed or unauthorized and drops it.

Resolution

To restore DHCP connectivity, implement one of the following architectural changes:

  • Migrate DHCP Services to NSX: Configure the DHCP server or a DHCP static binding directly on the NSX segment to eliminate cascading relays.

  • Disable ACI DHCP Snooping: Disable DHCP Relay and DHCP Snooping features on the Cisco ACI Bridge Domain to allow the fabric to act as a transparent Layer 3 transit for DHCP traffic.

  • Implement NSX L2 Bridge: Use an NSX L2 Bridge to extend the segment to the ACI fabric, allowing ACI to act as the primary and only DHCP relay agent.

Additional Information

Creating and Managing Broadcom Support Cases

Download Broadcom Products and Software