Created on
09-21-2025
11:12 PM
Edited on
10-29-2025
10:38 PM
By
Anthony_E
| Description |
This article describes the issue of being unable to enable the DHCP server in IPsec phase2 settings on a FortiGate and addresses how to resolve this issue, which involves disabling the mode configuration in phase1 settings. |
| Scope | FortiGate. |
| Solution |
To configure the DHCP server for the IPsec VPN tunnel interface on FortiGate. The users connecting to dial-up IPsec VPN will be assigned an IP address from the defined IP range.
config system dhcp server
To resolve the issue of being unable to enable the DHCP server in IPsec phase2 settings, perform the following steps:
next
To use the external DHCP server for IPSEC VPN clients, it is required to enable the DHCP relay on the tunnel interface under system interface settings and define the IP address of the DHCP server.
Use the commands below:
config system interface end
Related documents: Technical Tip: DHCP IP address reservation with Dial up IPsec VPN |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.