<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Site to Site vpn with Dhcp server at remote site in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-with-dhcp-server-at-remote-site/m-p/187784#M57087</link>
    <description>&lt;P&gt;It sounds like you need a security policy to permit the dhcp reply on the PA.&amp;nbsp; This would be from the zone of the tunnel interface to the zone where the client is connected to the network.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sat, 18 Nov 2017 11:54:40 GMT</pubDate>
    <dc:creator>pulukas</dc:creator>
    <dc:date>2017-11-18T11:54:40Z</dc:date>
    <item>
      <title>Site to Site vpn with Dhcp server at remote site</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-with-dhcp-server-at-remote-site/m-p/187632#M57065</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a site to site ipsec vpn between 2 PA devices. Lets call them Site A and Site B and at Site A I have a Cisco router acting as a dhcp server. I'm trying to have all the client at Site B get their dhcp address and scope options from the cisco router at Site A. I have the sites connected to each other and I setup a dhcp relay agent on Site B PA device. I can see the client making the request and the request hitting the dhcp server at the remote site, but I'm not receiving an IP address at the client. For simplicty, I created the vpn tunnel between the two sites to land in the same zone as the trusted.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I did see this thread &lt;A href="https://live.paloaltonetworks.com/t5/General-Topics/DHCP-relay-through-a-VPN-tunnel/m-p/65406/highlight/true#M39062" target="_blank"&gt;https://live.paloaltonetworks.com/t5/General-Topics/DHCP-relay-through-a-VPN-tunnel/m-p/65406/highlight/true#M39062&lt;/A&gt; only diffence is they're using an ASA.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've done this in the past with an ASA and I know it works, but I'm not sure if it works with Palo Alto. Does anyone have a senerio like this configured?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;S.&lt;/P&gt;</description>
      <pubDate>Fri, 17 Nov 2017 02:50:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-with-dhcp-server-at-remote-site/m-p/187632#M57065</guid>
      <dc:creator>strobins</dc:creator>
      <dc:date>2017-11-17T02:50:50Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site vpn with Dhcp server at remote site</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-with-dhcp-server-at-remote-site/m-p/187784#M57087</link>
      <description>&lt;P&gt;It sounds like you need a security policy to permit the dhcp reply on the PA.&amp;nbsp; This would be from the zone of the tunnel interface to the zone where the client is connected to the network.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 18 Nov 2017 11:54:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-with-dhcp-server-at-remote-site/m-p/187784#M57087</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2017-11-18T11:54:40Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site vpn with Dhcp server at remote site</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-with-dhcp-server-at-remote-site/m-p/187789#M57088</link>
      <description>&lt;P&gt;Hi Pulukas,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have them both on the trusted zone for simplicity. Do I still need a rule?&lt;/P&gt;</description>
      <pubDate>Sat, 18 Nov 2017 21:00:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-with-dhcp-server-at-remote-site/m-p/187789#M57088</guid>
      <dc:creator>strobins</dc:creator>
      <dc:date>2017-11-18T21:00:12Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site vpn with Dhcp server at remote site</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-with-dhcp-server-at-remote-site/m-p/187811#M57090</link>
      <description>&lt;P&gt;The default intrazone policy is to permit so if that has not been overridden it should work.&amp;nbsp; You can confirm the deployed rule.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Management-Articles/What-are-Universal-Intrazone-and-Interzone-Rules/ta-p/57491" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Management-Articles/What-are-Universal-Intrazone-and-Interzone-Rules/ta-p/57491&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Or just create an explict one for this traffic so you can see session init logs confirming the traffic arrives on the PA.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If the logs don't help we can try packet captures to confirm what is happening.&lt;/P&gt;</description>
      <pubDate>Sun, 19 Nov 2017 11:46:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-with-dhcp-server-at-remote-site/m-p/187811#M57090</guid>
      <dc:creator>pulukas</dc:creator>
      <dc:date>2017-11-19T11:46:36Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site vpn with Dhcp server at remote site</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-with-dhcp-server-at-remote-site/m-p/187813#M57091</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please attachet some pic to your main PA configurtion for DHCP Server and DHCP Relay&lt;/P&gt;</description>
      <pubDate>Sun, 19 Nov 2017 13:22:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-with-dhcp-server-at-remote-site/m-p/187813#M57091</guid>
      <dc:creator>MFayez</dc:creator>
      <dc:date>2017-11-19T13:22:05Z</dc:date>
    </item>
    <item>
      <title>Re: Site to Site vpn with Dhcp server at remote site</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-with-dhcp-server-at-remote-site/m-p/188657#M57223</link>
      <description>&lt;P&gt;Will do. When I get back. Have to run to one of our remote sites for 2 weeks.&lt;/P&gt;</description>
      <pubDate>Fri, 24 Nov 2017 13:29:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/site-to-site-vpn-with-dhcp-server-at-remote-site/m-p/188657#M57223</guid>
      <dc:creator>strobins</dc:creator>
      <dc:date>2017-11-24T13:29:08Z</dc:date>
    </item>
  </channel>
</rss>

