Fortinet Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
ChristianK
New Contributor

Usage of external DHCP on SSL VPN

Hello all,

I want to use external DHCP on my SSL VPN.

I found the following on the internet:

config system interface 
edit ssl.root
set dhcp-relay-service [enable|disable]
set dhcp-relay-ip next
end

 

Only with these settings, it's not working.

I think there is also a configuration need on VPN SSL web portal or VPN SSL setting or I have to assign an IP on the interface ssl.root

 

Does anyone here know about this? Can someone give me the winning tip?

1 Solution
Anonymous
Not applicable

Hello,

 

As per your query Fortinet now has this feature of having an external DHCP server for SSL VPN.

Please check the link below:

 

https://community.fortinet.com/t5/FortiGate/Technical-Tip-SSL-VPN-with-external-DHCP-Server/ta-p/215...

 

Thanks,

View solution in original post

2 REPLIES 2
Yurisk
Valued Contributor

This is a frequent trap - dhcp configs under ssl.root interface are there ... but they do not work.

May be in 7.0 it is different but for 6.x train it is possible for VPN SSL only if you use RADIUS for authentication and then your RADIUS server will allocate each user own IP address. Any other case - it is only VPN SSL pools on Fortigate or IPSec VPN (also part of FortiClient) - there you CAN use external DHCP server.

 

 

Yuri
https://yurisk.info/ blog: All things Fortinet, no ads.


All opinions are mine only.
Anonymous
Not applicable

Hello,

 

As per your query Fortinet now has this feature of having an external DHCP server for SSL VPN.

Please check the link below:

 

https://community.fortinet.com/t5/FortiGate/Technical-Tip-SSL-VPN-with-external-DHCP-Server/ta-p/215...

 

Thanks,