<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Different DHCP Subnets on same Interface in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/different-dhcp-subnets-on-same-interface/m-p/119482#M45799</link>
    <description>&lt;P&gt;You said: "&lt;SPAN&gt;The inside interface on PA is connected to a trunk on a switch and all the traffic to PA is untagged&lt;/SPAN&gt;"&lt;/P&gt;&lt;P&gt;But trunk always has tagged traffic. Otherwise trunk can't work.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So DHCP requests should arrive with correct VLAN tag and you can use subinterfaces. Actually you must use subinterfaces in this scenario otherwise only untagged (or vlan 1) traffic will be receieved by PA.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 17 Oct 2016 07:12:07 GMT</pubDate>
    <dc:creator>santonic</dc:creator>
    <dc:date>2016-10-17T07:12:07Z</dc:date>
    <item>
      <title>Different DHCP Subnets on same Interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/different-dhcp-subnets-on-same-interface/m-p/119081#M45739</link>
      <description>&lt;P&gt;Hello everyone,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;one of my customer has the following specific requirement.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PA500 version 7.1.0&lt;/P&gt;&lt;P&gt;Inside Interface IP: 10.0.1.1/24&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Firewall should act as DHCP Server and assign IP Addresses in the following Scopes only via inside interface.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Scope: LAN Devices&lt;/P&gt;&lt;P&gt;Range: 10.0.1.50-10.0.1.100 /24&lt;/P&gt;&lt;P&gt;Gateway: 10.0.1.254&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Scope: WAN Devices&lt;/P&gt;&lt;P&gt;Range: 10.0.25.50-10.0.25.100/24&lt;/P&gt;&lt;P&gt;Gateway: 10.0.25.254&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Scope: Voice&amp;nbsp;Devices&lt;/P&gt;&lt;P&gt;Range: 10.0.30.50-10.0.30.100/24&lt;/P&gt;&lt;P&gt;Gateway: 10.0.30.254&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So the questions are following:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. &amp;nbsp;Is such a configuration at all possible? The inside interface IP Subnet is different from WAN and Voice Scope.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2. The inside interface on PA is connected to a trunk on a switch and all the traffic to PA is untagged. How can PA differentiate whether the incoming DHCP request is from LAN device, WLAN device or a Voice device?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks and Regards,&lt;/P&gt;&lt;P&gt;R&lt;/P&gt;</description>
      <pubDate>Thu, 13 Oct 2016 13:42:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/different-dhcp-subnets-on-same-interface/m-p/119081#M45739</guid>
      <dc:creator>rjdahav163</dc:creator>
      <dc:date>2016-10-13T13:42:16Z</dc:date>
    </item>
    <item>
      <title>Re: Different DHCP Subnets on same Interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/different-dhcp-subnets-on-same-interface/m-p/119083#M45741</link>
      <description>&lt;P&gt;I believe that the only way to do this properly would be to setup LAN,WAN, and VOICE interfaces on your PA500 and then setup the DHCP for the interface, I believe that you can only have one DHCP scope on any particular interface.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PS. If they are running on 7.1.0 I would upgrade them to 7.1.5 and get the latest code; they have made a lot of bug fixes since 7.1.0.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Oct 2016 14:20:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/different-dhcp-subnets-on-same-interface/m-p/119083#M45741</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2016-10-13T14:20:14Z</dc:date>
    </item>
    <item>
      <title>Re: Different DHCP Subnets on same Interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/different-dhcp-subnets-on-same-interface/m-p/119084#M45742</link>
      <description>&lt;P&gt;Or you could&amp;nbsp;create a subinterfaces and have a DHCP server configured there for each&amp;nbsp;network&lt;/P&gt;</description>
      <pubDate>Thu, 13 Oct 2016 14:23:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/different-dhcp-subnets-on-same-interface/m-p/119084#M45742</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2016-10-13T14:23:20Z</dc:date>
    </item>
    <item>
      <title>Re: Different DHCP Subnets on same Interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/different-dhcp-subnets-on-same-interface/m-p/119102#M45753</link>
      <description>&lt;P&gt;Yeah subinterfaces was my initial thought, but they want that the inside interface has only one IP. For each subinterface I would need one IP from respective subnet each which is not possible &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Oct 2016 18:13:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/different-dhcp-subnets-on-same-interface/m-p/119102#M45753</guid>
      <dc:creator>rjdahav163</dc:creator>
      <dc:date>2016-10-13T18:13:49Z</dc:date>
    </item>
    <item>
      <title>Re: Different DHCP Subnets on same Interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/different-dhcp-subnets-on-same-interface/m-p/119160#M45785</link>
      <description>&lt;P&gt;How would the DHCP server possibly know which type of device was making the request in order to hand out the correct IP address?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Some DHCP servers have filters where you can use MAC address prefixes to do such things, but as far as I know, the Palo Alto DHCP server doesn't offer this.&lt;/P&gt;</description>
      <pubDate>Fri, 14 Oct 2016 19:19:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/different-dhcp-subnets-on-same-interface/m-p/119160#M45785</guid>
      <dc:creator>Ken_Cornetet</dc:creator>
      <dc:date>2016-10-14T19:19:37Z</dc:date>
    </item>
    <item>
      <title>Re: Different DHCP Subnets on same Interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/different-dhcp-subnets-on-same-interface/m-p/119482#M45799</link>
      <description>&lt;P&gt;You said: "&lt;SPAN&gt;The inside interface on PA is connected to a trunk on a switch and all the traffic to PA is untagged&lt;/SPAN&gt;"&lt;/P&gt;&lt;P&gt;But trunk always has tagged traffic. Otherwise trunk can't work.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So DHCP requests should arrive with correct VLAN tag and you can use subinterfaces. Actually you must use subinterfaces in this scenario otherwise only untagged (or vlan 1) traffic will be receieved by PA.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Oct 2016 07:12:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/different-dhcp-subnets-on-same-interface/m-p/119482#M45799</guid>
      <dc:creator>santonic</dc:creator>
      <dc:date>2016-10-17T07:12:07Z</dc:date>
    </item>
    <item>
      <title>Re: Different DHCP Subnets on same Interface</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/different-dhcp-subnets-on-same-interface/m-p/120387#M45905</link>
      <description>&lt;P&gt;This was exactly my argument with the customer. However his typical response is - "Other Firewall manufacturers are able to do that easily why not Palo Alto". &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Oct 2016 07:40:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/different-dhcp-subnets-on-same-interface/m-p/120387#M45905</guid>
      <dc:creator>rjdahav163</dc:creator>
      <dc:date>2016-10-21T07:40:47Z</dc:date>
    </item>
  </channel>
</rss>

