Skip to main content
LEO08
New Member
January 27, 2017
Solved

DHCP setup question

  • January 27, 2017
  • 1 reply
  • 7222 views

Hello,

 The Fortigate NGFW we are using in our current location is a 60D. The 60D is being used as the main firewall, DHCP and DNS device. I have been tasked to separate 2 departments into different networks but keep the same DHCP scope for the new networks. My plan is to divide these departments into VLANs however I don’t know if/how you can setup the Fortigate to provide one DHCP scope to separate VLANs.

Can I setup one VLAN to relay DCHP to the other VLAN?

    Best answer by rwpatterson

    Your best bet would be to 'fake out' the upper management, and split a class C in half. One VLAN gets the bottom half of the 25 bit subnet, the other VLAN the top. To the unknowledged it looks to be the sane subnet, but they are truly two unique subnets.

    1 reply

    Toshi_Esumi
    SuperUser
    SuperUser
    January 27, 2017

    I don't think you can, not because of FG, but two different boradcast domains (like VLANs in your case) need to have two different subnets and gateways then only Layer3 router can let them talk each other. To me 1 broadcast domain = 1 DHCP scope.

    boneyard
    Valued Contributor
    January 28, 2017

    i agree with Toshi Esumi, not possible because of how networking works.

     

    why do you want separate VLANs but the same IP range, that will only cause issues.

     

    how about two VLANs with different IP ranges and different DHCP scopes?

    rwpatterson
    New Member
    January 28, 2017

    Your best bet would be to 'fake out' the upper management, and split a class C in half. One VLAN gets the bottom half of the 25 bit subnet, the other VLAN the top. To the unknowledged it looks to be the sane subnet, but they are truly two unique subnets.