<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic IPSec and DHCP relay in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-and-dhcp-relay/m-p/232989#M66823</link>
    <description>&lt;P&gt;Can a DHCP relay be configured on the PA to be used by and IPSec tunnel also configured on the PA?&lt;/P&gt;</description>
    <pubDate>Fri, 28 Sep 2018 14:43:36 GMT</pubDate>
    <dc:creator>jdprovine</dc:creator>
    <dc:date>2018-09-28T14:43:36Z</dc:date>
    <item>
      <title>IPSec and DHCP relay</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-and-dhcp-relay/m-p/232989#M66823</link>
      <description>&lt;P&gt;Can a DHCP relay be configured on the PA to be used by and IPSec tunnel also configured on the PA?&lt;/P&gt;</description>
      <pubDate>Fri, 28 Sep 2018 14:43:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-and-dhcp-relay/m-p/232989#M66823</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2018-09-28T14:43:36Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec and DHCP relay</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-and-dhcp-relay/m-p/232998#M66826</link>
      <description>&lt;P&gt;What exactly do you mean with "be used by an IPSec tunnel" ??&lt;/P&gt;</description>
      <pubDate>Fri, 28 Sep 2018 15:17:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-and-dhcp-relay/m-p/232998#M66826</guid>
      <dc:creator>markus_w</dc:creator>
      <dc:date>2018-09-28T15:17:37Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec and DHCP relay</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-and-dhcp-relay/m-p/232999#M66827</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/74336"&gt;@markus_w&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are doing a virtual desktop trial with a vendor in the cloud, they are going to connect to us using a IPSec tunnel that we are going to set up on the palo alto firewall. So instead of putting DHCP server in the clouds to hand our IP addresses to the virutal desktop they are hosting for us we want them to connect and get IP addresses from our network DHCP servers. So.... I am trying to figure out if that is possible&lt;/P&gt;</description>
      <pubDate>Fri, 28 Sep 2018 15:24:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-and-dhcp-relay/m-p/232999#M66827</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2018-09-28T15:24:50Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec and DHCP relay</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-and-dhcp-relay/m-p/233010#M66832</link>
      <description>&lt;P&gt;Ok. As i know, it isn't possible because your setup is a Layer 3 VPN. DHCP works on layer 2 and even if your Cloud Provider offers a Layer 2 Tunnel like GRE, it isn't possible to terminate the Tunnel with a Palo Alto Networks Firewall.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;my advice:&lt;/P&gt;&lt;P&gt;1. You need a DHCP relay agent in the local subnet of your clients (or a dhcp server). Maybe the Gateway of your Cloud Provider can do it? Ask him.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;OR&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2. You could run a Palo Alto VM in the network of your Virtual Desktop Clients and use it as a DHCP Relay Agent or DHCP Server&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;OR&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;3. static ip adress.... (depends on your setup and your pain...)&lt;/P&gt;</description>
      <pubDate>Fri, 28 Sep 2018 15:43:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-and-dhcp-relay/m-p/233010#M66832</guid>
      <dc:creator>markus_w</dc:creator>
      <dc:date>2018-09-28T15:43:04Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec and DHCP relay</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-and-dhcp-relay/m-p/233014#M66834</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/74336"&gt;@markus_w&lt;/a&gt;&lt;/P&gt;&lt;P&gt;The provider can do it, but those in charge opted not to let the provider host it.&lt;/P&gt;</description>
      <pubDate>Fri, 28 Sep 2018 15:47:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-and-dhcp-relay/m-p/233014#M66834</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2018-09-28T15:47:55Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec and DHCP relay</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-and-dhcp-relay/m-p/233015#M66835</link>
      <description>&lt;P&gt;There Are No Technical Solutions to Human Problems. Sorry.&lt;/P&gt;&lt;P&gt;Maybe the Cloud Provider support IPv6 and IPv6 Autoconfiguration on his Gateway in the local Network?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And what do you mean with "to let the provider host it." ??&lt;/P&gt;&lt;P&gt;The Provider should not Host a VM Palo Alto or a DHCP Service?&lt;/P&gt;</description>
      <pubDate>Fri, 28 Sep 2018 15:56:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-and-dhcp-relay/m-p/233015#M66835</guid>
      <dc:creator>markus_w</dc:creator>
      <dc:date>2018-09-28T15:56:52Z</dc:date>
    </item>
    <item>
      <title>Re: IPSec and DHCP relay</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ipsec-and-dhcp-relay/m-p/233017#M66837</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/74336"&gt;@markus_w&lt;/a&gt;&lt;/P&gt;&lt;P&gt;I think that the vendor offers and option to host a DHCP server for the virtual desktops in the cloud.&amp;nbsp; but for what ever reason we decided to try to use our own.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 28 Sep 2018 16:34:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ipsec-and-dhcp-relay/m-p/233017#M66837</guid>
      <dc:creator>jdprovine</dc:creator>
      <dc:date>2018-09-28T16:34:34Z</dc:date>
    </item>
  </channel>
</rss>

