- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
11-16-2017 06:50 PM
Hi,
I have a site to site ipsec vpn between 2 PA devices. Lets call them Site A and Site B and at Site A I have a Cisco router acting as a dhcp server. I'm trying to have all the client at Site B get their dhcp address and scope options from the cisco router at Site A. I have the sites connected to each other and I setup a dhcp relay agent on Site B PA device. I can see the client making the request and the request hitting the dhcp server at the remote site, but I'm not receiving an IP address at the client. For simplicty, I created the vpn tunnel between the two sites to land in the same zone as the trusted.
I did see this thread https://live.paloaltonetworks.com/t5/General-Topics/DHCP-relay-through-a-VPN-tunnel/m-p/65406/highli... only diffence is they're using an ASA.
I've done this in the past with an ASA and I know it works, but I'm not sure if it works with Palo Alto. Does anyone have a senerio like this configured?
Thanks,
S.
11-18-2017 03:54 AM
It sounds like you need a security policy to permit the dhcp reply on the PA. This would be from the zone of the tunnel interface to the zone where the client is connected to the network.
11-18-2017 01:00 PM
Hi Pulukas,
I have them both on the trusted zone for simplicity. Do I still need a rule?
11-19-2017 03:46 AM
The default intrazone policy is to permit so if that has not been overridden it should work. You can confirm the deployed rule.
Or just create an explict one for this traffic so you can see session init logs confirming the traffic arrives on the PA.
If the logs don't help we can try packet captures to confirm what is happening.
11-24-2017 05:29 AM
Will do. When I get back. Have to run to one of our remote sites for 2 weeks.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!