Topology: <?xml:namespace prefix = "o" />

Software Version for both USG.
Huawei Versatile Security Platform Software
Software Version: USG6600 V100R001C30SPC600 (VRP (R) Software, Version 5.30)
Copyright (C) 2013-2016 Huawei Technologies Co., Ltd.
Configuration USG6600_FW1_FUAC
#
dhcp enable
#
hrp mirror session enable
hrp enable
undo hrp ospfv3-cost adjust-enable
hrp loadbalance-device
hrp interface GigabitEthernet1/0/0 remote 10.0.0.2
hrp interface GigabitEthernet1/0/2 remote 172.16.1.102
#
interface GigabitEthernet2/0/5
description To_WiFi
alias To_WIFI
ip address 172.16.48.2 255.255.240.0
dhcp select interface
dhcp server ip-range 172.16.48.100 172.16.63.254
dhcp server forbidden-ip 172.16.16.1 172.16.16.10
dhcp server forbidden-ip 172.16.17.1 172.16.17.10
dhcp server forbidden-ip 172.16.18.1 172.16.18.10
dhcp server forbidden-ip 172.16.19.1 172.16.19.10
dhcp server gateway-list 172.16.48.1
dhcp server dns-list 186.154.251.230 4.2.2.3
dhcp server domain-name fuac.edu.co
dhcp server expired day 0 hour 0 minute 15
vrrp vrid 7 virtual-ip 172.16.48.1 active
hrp track active
hrp track standby
lldp enable
lldp tlv-enable basic-tlv all
service-manage https permit
service-manage ping permit
service-manage ssh permit
bandwidth ingress 30000
bandwidth egress 30000
#
firewall zone name WIFI
description WIFI_FUAC
set priority 40
add interface GigabitEthernet2/0/5
#
ip address-set WiFi_172.16.48.0 type object
description WiFi
address 0 172.16.48.0 mask 20
#
ip address-set "GATEWAY WIFI" type object
description GATEWAY WIFI
address 0 172.16.16.2 mask 32
#
security-policy
rule name WiFi_To_INET
policy logging
session logging
source-zone WIFI
destination-zone untrust
source-address address-set WiFi_172.16.48.0
action permit
rule name Gestion_Equipos_LAN
description Gestion_Equipos
policy logging
session logging
source-zone WIFI
destination-zone LAN
action permit
rule name "DMZ TO FIREWALL TO DHCP"
description DMZ TO FIREWALL TO DHCP
disable
source-zone dmz
destination-zone trust
destination-address address-set "GATEWAY WIFI"
action permit
Configuration USG6600_FW2_FUAC
#
dhcp enable
#
hrp mirror session enable
hrp enable
undo hrp ospfv3-cost adjust-enable
hrp loadbalance-device
hrp interface GigabitEthernet1/0/0 remote 10.0.0.1
hrp interface GigabitEthernet1/0/2 remote 172.16.1.104
#
interface GigabitEthernet2/0/5
description To_WiFi
alias To_WIFI
ip address 172.16.48.3 255.255.240.0
dhcp select interface
dhcp server ip-range 172.16.48.100 172.16.63.254
dhcp server forbidden-ip 172.16.16.1 172.16.16.10
dhcp server forbidden-ip 172.16.17.1 172.16.17.10
dhcp server forbidden-ip 172.16.18.1 172.16.18.10
dhcp server forbidden-ip 172.16.19.1 172.16.19.10
dhcp server gateway-list 172.16.48.1
dhcp server dns-list 186.154.251.230 4.2.2.3
dhcp server domain-name fuac.edu.co
dhcp server expired day 0 hour 0 minute 15
vrrp vrid 7 virtual-ip 172.16.48.1 standby
hrp track active
hrp track standby
lldp enable
lldp tlv-enable basic-tlv all
service-manage https permit
service-manage ping permit
service-manage ssh permit
bandwidth ingress 30000
bandwidth egress 30000
#
firewall zone name WIFI
description WIFI_FUAC
set priority 40
add interface GigabitEthernet2/0/5
#
ip address-set WiFi_172.16.48.0 type object
description WiFi
address 0 172.16.48.0 mask 20
#
ip address-set "GATEWAY WIFI" type object
description GATEWAY WIFI
address 0 172.16.16.2 mask 32
#
security-policy
rule name WiFi_To_INET
policy logging
session logging
source-zone WIFI
destination-zone untrust
source-address address-set WiFi_172.16.48.0
action permit
rule name Gestion_Equipos_LAN
description Gestion_Equipos
policy logging
session logging
source-zone WIFI
destination-zone LAN
action permit
rule name "DMZ TO FIREWALL TO DHCP"
description DMZ TO FIREWALL TO DHCP
disable
source-zone dmz
destination-zone trust
destination-address address-set "GATEWAY WIFI"
action permit
#
Symptom:
Users connected on WiFi Network should get IP-Address dynamically, but around 300 users can get IP successfully others cannot, even the Pool support 4094 Host.
DHCP Server configured on Interface GigabitEthernet 2/0/5
GigabitEthernet2/0/5 current state : UP
Line protocol current state : UP
The Maximum Transmit Unit : 1500 bytes
input packets : 71834, bytes : 9377678, multicasts : 70553
output packets : 3910, bytes : 343776, multicasts : 3368
Directed-broadcast packets:
received packets: 915, sent packets: 34
forwarded packets: 0, dropped packets: 0
ARP packet input number: 22730
Request packet: 22649
Reply packet: 81
Unknown packet: 0
Internet Address is 172.16.48.2/20
Broadcast address : 172.16.63.255
TTL invalid packet number: 0
ICMP packet input number: 10
Echo reply: 9
Unreachable: 1
Source quench: 0
Routing redirect: 0
Echo request: 0
Router advert: 0
Router solicit: 0
Time exceed: 0
IP header bad: 0
Timestamp request: 0
Timestamp reply: 0
Information request: 0
Information reply: 0
Netmask request: 0
Netmask reply: 0
Unknown type: 0
DHCP packet deal mode: interface




