Why empty trusted relays drop your helpers

You pointed ip helper-address at Lattice and the VLAN stayed quiet. Empty Trusted relays drop relayed DHCP. List helper IPs before you point the helper.

Sep 22, 2026 · Query: why empty trusted relays drop helpers

You pointed ip helper-address at Lattice. The VLAN stays quiet. Overview does not move. Work is empty. The first instinct is “dhcpd is broken.”

Usually it is not.

Lattice drops relayed DHCP when Trusted relays is empty. That is the design. The helper IPs that will unicast Discover to this node (or the HA VIP) belong in More → Settings → Trusted relays. Until they are listed, relayed packets do not become Offers.

Helpers are not broadcasts

Campus VLANs almost never send broadcast Discover to the DHCP server. The L3 switch or firewall takes the client packet and unicasts it. The giaddr in that packet is the relay’s address — usually the gateway you typed on the subnet.

Lattice must trust that source. Empty trusted relays means: drop relayed DHCP. Local prove paths still work. Relayed campus traffic does not.

The first-subnet docs say it in one line: empty drops relayed DHCP. Add the L3 switch / firewall IPs that will ip helper-address here. Then point one helper at this VM (or the VIP). Do not dual-helper Windows DHCP and Lattice on the same VLAN.

Prove local first, then open the relay

Prefix → subnet → don’t-offer the gateway → pool. Option 6 = the resolvers laptops already query. That map is not a lease yet. You need a DHCP packet.

On the Ubuntu node, with no relay in the path yet:

lattice-dhcptest -server 127.0.0.1:67 -giaddr 10.20.20.1

-giaddr must sit inside the subnet CIDR. The gateway you typed is the usual choice. Overview should show a live lease, not only Expired.

A Windows laptop on the same VLAN as Community dhcpd sending a broadcast Discover often never arrives (Docker). That does not mean the install failed. Use a relay. Or use the local test. Then list the real helper IPs in Trusted relays and cut one VLAN.

What “empty” feels like on Tuesday

Helpdesk pastes a MAC. Search finds nothing. Neteng checks the helper. The helper is correct. The subnet has a pool. The reservation row is there.

Trusted relays is still blank.

Work will not invent a queue for “you forgot the allow-list.” Relays is a named Work queue when traffic arrives and something else is wrong — wrong giaddr, leftover Windows scope, stale reservation. Empty trusted relays never reaches that path. The packet is dropped before the catalog gets a chance.

Fix: Settings → Trusted relays → the helper IPs. One helper per VLAN at cutover. Confirm giaddr matches a subnet CIDR you actually created. Prove with Overview live count and Leases for that MAC.

Cutover order that avoids the trap

Install Lattice beside the old server. Relays still point at the old box. Recreate intent: prefix, subnet, exclude gateway/VIP, pool, reservations, options. Dark: dhcpd may run, but nothing relays to it yet.

When you are ready for one VLAN:

  1. List that relay in Settings → Trusted relays.
  2. Point that one ip helper-address at Lattice (or the VIP).
  3. Deactivate new Offers on the old scope the same hour.
  4. Watch Overview and NAK logs.

Do not leave both offering on the same giaddr. Do not run Microsoft and Lattice on the same UDP VIP. Rollback is relays back to the old server — cleanest before many clients rediscover.

Failover partners do not come with you on migrate. Live leases do not import. Relays stay on the L3 gear; only the helper target changes. That is why trusted relays matter on day one of every VLAN you cut.

Catalog model, not a firewall theater

Trusted relays is part of operating one catalog. Prefixes, subnets, pools, reservations, leases — dhcpd serves those rows. The console writes them. There is no second copy to sync. The reservation you save is the next Offer. Helpers are how Discover reaches that catalog from remote VLANs.

Same pool on every node once you are on paid HA: Discover on one node and Ack on another is the same lease. Relays still point at one VIP. Health is HTTP /readyz, not “restart the primary.” Community stays one Ubuntu node. Same tarball. No phone-home.

Soft path in

Community is the install with no license file: 1,000 managed IPs, one node. Managed IPs = leased + reserved + quarantined + assigned. A 30-day Starter trial in the portal tests extra dhcpd and three-node VIP before you buy. Paid files upload on that cluster — no reinstall (Signup, Pricing).

For the first subnet path, read First subnet. For the cutover playbook, read Migrate. The product compare is Replace Windows DHCP. Soft-link the live Windows Notes — Why switch off Windows DHCP and the spreadsheet and How to dump Windows DHCP scopes — this piece is the relays allow-list only.

Empty trusted relays drop your helpers on purpose. List the IPs. Then point the helper. Then prove the Ack.

FAQ

Why is Overview empty after I pointed ip helper-address at Lattice?
Lattice drops relayed DHCP when Trusted relays is empty. List the helper IPs in Settings → Trusted relays, then point one helper. First subnet.
Should I dual-helper Windows DHCP and Lattice on the same VLAN?
No. One helper per VLAN at cutover. Do not leave both offering on the same giaddr. Do not run Microsoft and Lattice on the same UDP VIP. Read the migrate playbook.
Do failover partners or live leases come with you?
No. Failover partners do not come with you on migrate. Live leases do not import. Relays stay on the L3 gear; only the helper target changes. Microsoft failover partners don’t come with you.