Is it possible to use DHCP relay to pass SSLVPN IP requests to a true DHCP server instead of just using an SSLVPN Address Pool?
I see in the ssl.root interface, through CLI, the ability to enable DHCP relay, but not sure if this will work or not.
Scenario I've been asked for by a client is DHCP Options for a VOIP phone. They use SSLVPN in tunnel mode for remote connection to their offices. My first thought was, how would the phones be using SSLVPN? It turns out they plug the phone in to their PC (which is connected via tunnel) and the phone expects to get a config file via configured DHCP options. It's a strange setup, for sure - and I've reached back to my client contact to see if there's any other automated way they could put the config details on the phone.
Thanks for any thoughts on this.
Did you ever get this to work?
I'm in the same situation and I want remote users to get their DHCP address from an External DHCP-server and not the buildt in Scoop.
EDIT:
Found it!
config system interface edit ssl.root set dhcp-relay-service [enable|disable] set dhcp-relay-ip next end
Hello
Nilsan and works the DHCP-Relay configuration for the SSL.Root ?
Hello,
If we check the SLL VPN Guide , page 17: http://docs.fortinet.com/..rtigate-ssl-vpn-3 We have IP addresses for users and DHCP relay of IP address. If we check DHCP relay of IP address we can see that DHCP relay in SSL VPN is not for the users but for FortiGate. The FortiGate can get an IP address via DHCP server for SSL VPN services. If we check ssl vpn setting you do not have any configuration about DHCP. If you want use DHCP relay, I can recommend you IPSec, please refer IPsec VPN Guide: [link]http://docs.fortinet.com/d/fortigate-ipsec-vpn-520[/link]
Kind regards
Chavdar Tanev Fortinet EMEA TAC Engineer Level 1 Fortinet NSE 4 Certified
Page 804 in the 6.0.9 CLI guide.
https://docs.fortinet.com/document/fortigate/6.0.0/cli-reference/417537/system-interface
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1740 | |
1109 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.