Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
julianhaines
New Contributor

planning to move away from using an Address Range to allocate DHCP addresses

Good day,

 

I am planning to move away from using an Address Range to allocate DHCP addresses to my SSL VPN full tunnel clients to using a Windows 2016 DHCP server, I have a FortiGate FGT200F running firmware 7.x.

The current Windows DHCP server is already set up with multiple scopes and uses VLANs to determine which to allocate based on this.

I have done some research, and it looks like all I need to do is:

  1. Create a new add Address Range on the FortiGate with the new DHCP range.
  2. Create a new DHCP scope on the Windows server with the new DHCP range.
  3. Enable the DHCP proxy on the FortiGate
    1. Config -> System -> Settings
    2. set dhcp-proxy enable
    3. set dhcp-server-ip <dhcp-server-ip>
    4. end
    5. config vpn ssl web-portal
    6. edit “Portal-Tunnel”
    7. set ip-mode dhcp
    8. set dhcp-ra-giaddr <any-ip-in-dhcp-range>
    9. end
  4. Update the FortiGate Firewall SSL VPN policies to use the new Address Rage for the Incoming and Outgoing SSL VPN connections.

For the DHCP server to know which range to allocate to the SSL VPN users the dhcp-ra-giaddr option will be used instead of using VLANs.

 

Does this look good? Some of the commands are to set web-portal settings but I have the SSL VPN web portal access disabled so not sure if this is correct?

 

Thanks

1 REPLY 1
ozkanaltas
Valued Contributor III

Hello @julianhaines ,

 

Your configuration steps seem correct. 

 

For 5. step, this command says "vpn ssl web-portal" but, don't let this confuse you, this is actually required to configure the VPN in tunnel mode.

If you have found a solution, please like and accept it to make it easily accessible to others.
NSE 4-5-6-7 OT Sec - ENT FW
If you have found a solution, please like and accept it to make it easily accessible to others.NSE 4-5-6-7 OT Sec - ENT FW
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors