I'm working with a FortiGate running version 7.4.9. The current setup has a single subnet between the FortiGate and our on-prem router. However, behind that router, there are many VLANs and subnets on the LAN. I’d like to move DHCP services for those internal VLANs to the FortiGate, but the FortiGate doesn’t currently have Vlan interfaces or routes for those downstream subnets.
What’s the best way to configure DHCP on the FortiGate in this scenario?
Or is there a way for the FortiGate to serve DHCP to those VLANs without having direct interfaces in each subnet?
I have the DHCP Helper disabled but already setup. How do you Name the DHCP Vlans?
I also didn't see a way to name the scopes?
Thanks in advance for any guidance!
FortiGate
This helps a lot. I emailed my SE for a Feature Request about the Scope naming, I don't see it ANYWHERE in the cli. On 30+ different scopes it makes it a huge pain.
This is a little scary, Since they will all be the same relay agent.
"When the IP pool is exhausted, the DHCP daemon assigns the IP from other pools that have the same relay agent."
Is there a max amount of dhcp scopes?
FW-01 # config system dhcp server
FW-01 (server) # edit 12
Command fail. Return code -4 (reached the maximum number of entries)
depending on the model. But the smallest ones like 40F, 30G has max 32. You can check it below:
https://docs.fortinet.com/max-value-table
You wouldn't be able to choose 7.4.9 yet but 7.4.8 should have the same limit.
Toshi
32 is still far.
Can it be caused by system.dhcp.server:ip-range is limited to 10?
Yea I got it up to 33 but I think the limit is 32. Also setting the Name would be awesome for each scope..
I was thinking "edit 12" might not the highest number in the "config sys dhcp server".
Toshi
I see the output has exactly 32 servers and number 12 is a gap. That's why.
I have 36 scope to migrate from a dnsmasq server. https://github.com/leifdavisson/notes/blob/main/dnsmasq%20config%20to%20fortigate.ps1.txt
User | Count |
---|---|
2640 | |
1401 | |
810 | |
686 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.