DHCP Issues
Deploying a Fortigate 60D-POE and found a few issues with DHCP as we transition from our Juniper SSG.
1) Every Reserved IP must have a pool behind it.
2) Because of #1 we must create multiple pools.
3) Limited to a max of 3 IP pools per interface/subnet.
We do a lot of IP segmentation to assist with our firewall policy like the following:
.40-.50 are assigned to group 1 and they are allowed access to X,Y
.60-.70 are assigned to group 2 and they are allowed access to Z
.90-.100 are assigned to group 3 and they are allowed access to scheduled Z
.110-.120 are the general pool to which any visitor can connect and they are allowed to site 1.
I am unable to find a clean way of setting this up. If I make a class C pool, I then have to block out a whole lot of addresses.
Any ideas?