HI All,
I'm trying to support a Dialup IPsec clients which requires Mode Config to be enabled, and to use an external DHCP server to provide the dynamic IP address.
I've enabled Mode Config and DHCP under the phase1-interface. I've also enabled dhcp-proxy and configured a dhcp-server-ip under 'config system settings' as per the Fortinet documentation.
What I'm seeing is the FG is relaying the DHCP discover packet to my DHCP server, however the source IP address of the packet is incorrect. The IP I'm seeing is the FG interface IP from the network where the DHCP is located. What needs to happen is the FG needs to relay and use a source IP address from the VPN address pool/range or the IP on of the VPN interface, so that the DHCP server can know which IP range to use for this client.
I've tried setting a static IP on the VPN interface but didn't work either. Is there a way to control which source IP address the FG uses when it relays the DHCP discover (when Mode Config with DHCP is used)?
Thanks in advance
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Can you use a dhcp relay agent and id for this ? What does the dhcp-server support?
Ken Felix
PCNSE
NSE
StrongSwan
The DHCP is the latest Windows Server and I can see it does support relay agent ID policies, so that could work.
However another issue I'm seeing now is that when the Fortigate relays the DHCP discover it's putting it's own interface MAC address as the 'Client MAC address' in the DHCP packet, instead of the VPN client. The idea behind this was to setup static MAC to IP reservations on the DHCP server for VPN clients so that certain clients would always get the same IP address.
Hi,
This is a known issue. Only in FortiOS 6.4 was it added the ability to specify an IP address as a DHCP helper, so that the DHCP server returned addresses from the specified range.
The solution is to use the following option to tell the vpn the ip of the interface.
set dhcp-ra-giaddr 10.200.2.1
However, it seems not possible to make ip reservations on the DHCP server because the identifiers are of type "6869" and not 00: 37: 6C: E2: EB: 62.
Do you have a solution for this?
Option: (61) Client identifier
Length: 7
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1645 | |
1070 | |
751 | |
443 | |
210 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.