Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
PCNSE
NSE
StrongSwan
Again, knowing that I know nothing about phone servers (and we don' t manage or have anything to do with it other than it' s a VM on our hardware), when I do DHCP relay, those phones will have to get 10.10.20.x addresses from the phone server in order for voice traffic to route back to Office A' s Adtran/T1, correct? If that' s the case, from a theoretical position, how does the DHCP server know that local subnetted voice VLAN phones get 10.10.10.x addresses and DHCP relayed phones on Office B' s voice VLAN get 10.10.20.x addresses?This would be determine by the relay-dhcp-server ip address of office B router nic ( the firewall ip_address) aka properly as the GIADDR in the dhcp-message e.g config sys interface edit vlan2 set ip 10.10.20.1/24 set dhcp-relay-service enable set dhcp-relay-type regular set dhcp-relay-ip 10.10.10.200 192.168.100.200 192.168.200.200 â†-- this is the dhcp-server (s) end So the DHCP relay-agent ( firewall ) will present it’s address to the DHCP-server & the scope would be correctly served based on the relay-agent address
Another few quick (hopefully) questions on the DHCP relay setup since I' ve not done that before and documentation isn' t exactly helpful on the particulars: 1. Do I relay through the System > Network > Interfaces > Wan1 > Office_B_to_A tunnel (sub)interface?On firewall B you would have a dhcp-relay mode set for this firewall ( see the above cfg )
2. What is the difference between Regular and IPsec relaying (this is where documentation fails)?fortigate supports various dhcp-server types depending on FortiOS ver 1: regular ( what we use for a typical LAN ) 2: ipsec ( clients that used ipsec-dhcp for configuration vrs auto-configuration request & the client sends a classic dhcpdiscover message ) 3: relay ( where your dhcp-server is external & the address/assignment/binding is done off the local L3 device and remotely managed ) FWIW: Also I know you have the phone-server DHCP-server, but you could manage the scope on any of the other 2 dhcp-server if you wanted ( Office A or B ). So if you see in my earlier example, I gave you 3 dhcp-servers all ending in .200. You would replace these with the appropriate dhcp-server that you configure the phone-dhcp-scope on. I myself have never relayed over a ipsec-vpn, but have relayed locally to external dhcp-server off the fortigate in the past. Keep your design simple & let us know how it works out. If you need diagnostics, you can tcpdump on either the tunnel-interface leading to OfficeA or OfficeA interface leading to the dhcp-server to ensue the dhcp-relay is working and what address or you can run ; e.g diag sniffer packet <my interface> " host 10.10.10.200“ or diag debug enable diag debug application dhcprelay 250 on officeB I hope this all helps
PCNSE
NSE
StrongSwan
PCNSE
NSE
StrongSwan
PCNSE
NSE
StrongSwan
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1713 | |
1093 | |
752 | |
447 | |
231 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.