<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: DHCP relay issue in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/dhcp-relay-issue/m-p/449528#M100947</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/156321"&gt;@stef&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;The traffic on the firewall will simply look like the client is communicating directly to the DHCP host that you have setup as the relay target, so make sure that you are actually allowing the traffic properly in your rulebase. Use the 'test security-policy-match' command to verify that you actually have the security rulebase entry built out properly.&lt;/P&gt;</description>
    <pubDate>Thu, 25 Nov 2021 23:44:29 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2021-11-25T23:44:29Z</dc:date>
    <item>
      <title>DHCP relay issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dhcp-relay-issue/m-p/449394#M100928</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have an issue with the DHCP.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have DHCP relay configured on the device (PA820), remote windows server, connectivity and &amp;nbsp;policy permitting DHCP traffic.&lt;/P&gt;&lt;P&gt;The problem is that the traffic is sill dropped by the FW, classified as not applicable.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2021-11-25 at 11.56.38.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/37798iE90E1E7BBAA23729/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Screenshot 2021-11-25 at 11.56.38.png" alt="Screenshot 2021-11-25 at 11.56.38.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2021-11-25 at 11.58.01.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/37799i58B95E9C40E41939/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Screenshot 2021-11-25 at 11.58.01.png" alt="Screenshot 2021-11-25 at 11.58.01.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;Can someone advice &amp;nbsp;? Thank you in advance!&lt;/P&gt;</description>
      <pubDate>Thu, 25 Nov 2021 10:16:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dhcp-relay-issue/m-p/449394#M100928</guid>
      <dc:creator>stef</dc:creator>
      <dc:date>2021-11-25T10:16:42Z</dc:date>
    </item>
    <item>
      <title>Re: DHCP relay issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dhcp-relay-issue/m-p/449504#M100940</link>
      <description>&lt;P&gt;Keep in mind that DHCP is a conversation that happens before there is an IP address assigned, so the concept of a session might be different. I have not tested this on Palo myself. Maybe add both zones on the source and dest. My experience was Cisco ISR ACL and that was quite interesting.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClFXCA0" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClFXCA0&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Nov 2021 22:33:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dhcp-relay-issue/m-p/449504#M100940</guid>
      <dc:creator>johnwalshaw</dc:creator>
      <dc:date>2021-11-25T22:33:59Z</dc:date>
    </item>
    <item>
      <title>Re: DHCP relay issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dhcp-relay-issue/m-p/449528#M100947</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/156321"&gt;@stef&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;The traffic on the firewall will simply look like the client is communicating directly to the DHCP host that you have setup as the relay target, so make sure that you are actually allowing the traffic properly in your rulebase. Use the 'test security-policy-match' command to verify that you actually have the security rulebase entry built out properly.&lt;/P&gt;</description>
      <pubDate>Thu, 25 Nov 2021 23:44:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dhcp-relay-issue/m-p/449528#M100947</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2021-11-25T23:44:29Z</dc:date>
    </item>
  </channel>
</rss>

