Skip to main content
jfernandz
New Member
May 31, 2021
Question

DHCP servers in VLANs

  • May 31, 2021
  • 7 replies
  • 15776 views

I'm curious ... if I create two VLANs interfaces (attached to a particular physical interface, of course) and I enable for them the DHCP server, how are IPs for connected devices issued? I mean, I just can connect a host/device/client to the physical interface, so ... which DHCP would issue the IP for this host recently connected?   

 

Thank you all.

    7 replies

    sw2090
    SuperUser
    SuperUser
    May 31, 2021

    If you configure a DHCP Server on a FGT it is always tied to an interface - either physical,switch or vlan interface :)

    THat means that DHCP will onl listen on the interface it is tied to.

    So e.g. only a client that comes from out of vid1 via vlan vid1 interface will get an ip from a dhcp configured on vlan vid1 interface.

    Annother DHCP for annother vlan will not see this request because it doesn't hit the interface it is listening on.

    jfernandz
    jfernandzAuthor
    New Member
    May 31, 2021

    sw2090 wrote:

    If you configure a DHCP Server on a FGT it is always tied to an interface - either physical,switch or vlan interface :)

    THat means that DHCP will onl listen on the interface it is tied to.

    So e.g. only a client that comes from out of vid1 via vlan vid1 interface will get an ip from a dhcp configured on vlan vid1 interface.

    Annother DHCP for annother vlan will not see this request because it doesn't hit the interface it is listening on.

    What's `vid1 interface`?  My point is these two client will be connected to the same physical interface, so how would each DHCP for each VLAN distinguish to which VLAN does the client want to connect to? 

       
    sw2090
    SuperUser
    SuperUser
    May 31, 2021

    vid1 interface is an interface configured for vlan id 1. Just as example.

    In fact if the clients are in different vlans they are connected to the same PHYSICAL interface, though the FortiGate threats a vlan as a virtual interface. So traffic will come in via the PHYSICAL interface but it will hit the corresponding VIRTUAL vlan interface accoarding to vlan id in the packet. Only traffic that does not have a vlan id will hit the PHYSICAL interface.

    And your DHCP Servers on the FGT will be tied to the virtual vlan interfaces...

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.