10-22-2021 01:48 PM
Hi All,
I am running PanOS 10.1.0 vm image. Devices are connected as mentioned below.
Firewall E1/2 ---> L3 switch ---> Vlan 10, Vlan 20
I would really appreciate if some can tell me how to configure two DHCP scopes for Vlan 10 and Vlan 20 in PA firewall because once I configured one scope under E1/2 , for second scope E1/2 is not appearing.
I would really appreciate your help.
Thank You,
Gayan
10-22-2021 03:34 PM
Thank you for posting question @gayansa.samarakoon
The DHCP server is bound to an interface. This is one of the pre-requisite: https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-admin/networking/dhcp/configure-an-interface-as... Once you assign an interface to one pool, you will have to create a new interface for other pool.
If possible, could you configure on PA side sub-interfaces Eth1/2.10 and Eth 1/2.20 and assign an IP address to each interface, then configure E0/0 on R6 as dot1.q trunk and add Vlans 10 and 20 to the trunk? In this way you will be able to create a separate DHCP pool for Vlan 10 and 20. If you have configured an SVI interface as Gateway in R6 for Vlans 10 and 20, could you move it to PA sub-interfaces Eth1/2.10 and Eth 1/2.20 and assign them as Gateway DHCP option? After this, clients in Vlans 10 and 20 should be able to get an IP address from PA.
Kind Regards
Pavel
10-22-2021 03:34 PM
Thank you for posting question @gayansa.samarakoon
The DHCP server is bound to an interface. This is one of the pre-requisite: https://docs.paloaltonetworks.com/pan-os/10-0/pan-os-admin/networking/dhcp/configure-an-interface-as... Once you assign an interface to one pool, you will have to create a new interface for other pool.
If possible, could you configure on PA side sub-interfaces Eth1/2.10 and Eth 1/2.20 and assign an IP address to each interface, then configure E0/0 on R6 as dot1.q trunk and add Vlans 10 and 20 to the trunk? In this way you will be able to create a separate DHCP pool for Vlan 10 and 20. If you have configured an SVI interface as Gateway in R6 for Vlans 10 and 20, could you move it to PA sub-interfaces Eth1/2.10 and Eth 1/2.20 and assign them as Gateway DHCP option? After this, clients in Vlans 10 and 20 should be able to get an IP address from PA.
Kind Regards
Pavel
10-24-2021 11:14 AM
Hi Pavel,
Thanks a lot for your prompt reply and valuable insight regarding this issue.
Regards,
Gayan
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!