
Not applicable
Created on 04-29-2010 03:24 AM
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Transparent mode - how to allow DHCP from router?
Hello, I am a new owner, my network is very simple
internet > router > fortigate 50b > switch > PCs
My router (dlink) is acting as DHCP server
The problem that I have is that when a PC is turned on, it tries to get a new IP address from the router, but the firewall blocks the connection, so it can' t get a new ip. of course it can if I set a static IP address
For now I have solved with this rule: from any to any, source all destination all, DHCP service ACCEPT
but I' m wondering if this might cause security issues? is there maybe a better way to set this? thanks
5 REPLIES 5
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Your solution would be a DHCP helper. Under DHCP, you tell the FGT where to send requests received on the internal port. Just send them the the DLink IP address. No policies needed.
NOTE: I know this works in NAT/Route mode. Not sure of transparent. Give it a whirl.
Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com
Bob - self proclaimed posting junkie!See my Fortigate related scripts
at: http://fortigate.camerabob.com

Not applicable
Created on 04-29-2010 05:18 AM
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Under DI really appreciate your answer, it sounds logic but I' m confused because you said " no policies" ... then where should I set such thing?
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
DHCP relay is only for layer3 (Nat/Route mode). The configuration you have to allow DHCP is correct.
from internal to wan1 allow DHCP
[link=http://logMojo.com]logMojo[/link] by Security Confidence
Cloud Based - Logging â— Alerting â— Reporting â— Monitoring â— Management
Signup today!
[link=http://logMojo.com]logMojo[/link] by Security Confidence Cloud
Based - Logging â— Alerting â— Reporting â— Monitoring â— Management
Signup today!
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
ORIGINAL: SECCON1MC DHCP relay is only for layer3 (Nat/Route mode). The configuration you have to allow DHCP is correct. from internal to wan1 allow DHCP...need caffeine...
Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com
Bob - self proclaimed posting junkie!See my Fortigate related scripts
at: http://fortigate.camerabob.com

Not applicable
Created on 04-29-2010 05:36 AM
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
i tried that, it doesn' t work (internal -> wan)
the only thing that works is any to any.....
don' t ask me why
