Configuring PA-5250 to act as gateway for guest wireless

Showing results for 
Show  only  | Search instead for 
Did you mean: 
Please sign in to see details of an important advisory in our Customer Advisories area.

Configuring PA-5250 to act as gateway for guest wireless

L1 Bithead

Hi All,


I'm attempting to configure a 5250 to act as the gateway and DHCP server for my guest wireless. I have a Cisco 9800 WLC directly connected via fiber from Gi0/2 to Eth1/15 on the 5250 over VLAN 825. I then created VLAN 825 on the 5250 as an SVI and associated it with Eth1/15. I have a DHCP server setup to hand out IPs from the subnet. My APs are communicating fine via my internal coporate network however I can't seem to get an IP address from the FW. I also can't set a DNS server to be handed out via DHCP. Eth1/15 is currently a layer 2 port. I'm wondering if I need to make Eth1/15 a layer 3 port and move the gateway from the VLAN 825 interface to Eth1/15.


Cyber Elite
Cyber Elite

If you take packet capture on Palo interface Eth1/15 do you see incoming DHCP discover packets?

Enterprise Architect, Security @ Cloud Carib Ltd
Palo Alto Networks certified from 2011

Cyber Elite
Cyber Elite


Take a look at the logs and see where the traffic is getting blocked. If the DHCP server is not on the same vlan, the layer 3 interface on the vlan will be the one responsible for the dhcp relay.


  • 2 replies
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!