- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
03-03-2016 04:56 AM
I'm trying to get pxe boot to work through the firewall. Now options 66 and 67 are available in palos dhcp server but I can't get it to work anyway.
Besdies normal dhcp options I've setup option 66 with IP and ip-address and option 67 with ASCII and \path\bootfile
I have a sec pol with any any to the sccm server.
All I can see is tftp traffic hitting the gateway, no traffic trying to hit the sccm server at all.
So I'm thinking I've setup the dhcp server wrong.
Any ideas?
03-03-2016 05:09 AM
Nope.
I have on other interfaces but here I have a server.
03-03-2016 05:13 AM
Are you saying that you have configured dhcp server somewhere on your network and firewall is droping some dhcp traffic? I think you need to configure dhcp replay and create proper security policies.
03-03-2016 05:15 AM
No I'm saying that I've configured Palos own dhcp server with custom options 66 and 67.
03-03-2016 05:21 AM
Few suggestions that you may try:
> Remove any App Over-ride policy
> Remove QoS if you have it config
03-03-2016 05:27 AM
Nothing of those in place.
Just to clarify. Client gets ip, dns etc from palos dhcp server. Lease is 192.168.0.100/24 gw 192.168.0.1 (palo). Option 66 says 192.168.1.23.
Only traffic I can see is udp/69 with destination 192.168.0.1.
03-03-2016 05:29 AM
Try dhcp option 66 with ASCII and type the hostname of the tftp server not the ip address.
03-03-2016 05:31 AM
I have already tried that but no go I'm afraid.
03-03-2016 05:34 AM
Configure only option 66 first and don't configure option 67 check if only option 66 is working or not. Take pcap on the firewall you will get to know if firewall is sending packets with proper option or not.
10-01-2019 11:51 PM
Sorry late reply...
No we didn't and it was only for testing purposes so we didn't put that much effort into it.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!