Enhanced Security Measures in Place:   To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.

Site to Site vpn with Dhcp server at remote site

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Site to Site vpn with Dhcp server at remote site

L1 Bithead

Hi,

 

I have a site to site ipsec vpn between 2 PA devices. Lets call them Site A and Site B and at Site A I have a Cisco router acting as a dhcp server. I'm trying to have all the client at Site B get their dhcp address and scope options from the cisco router at Site A. I have the sites connected to each other and I setup a dhcp relay agent on Site B PA device. I can see the client making the request and the request hitting the dhcp server at the remote site, but I'm not receiving an IP address at the client. For simplicty, I created the vpn tunnel between the two sites to land in the same zone as the trusted.

 

I did see this thread https://live.paloaltonetworks.com/t5/General-Topics/DHCP-relay-through-a-VPN-tunnel/m-p/65406/highli... only diffence is they're using an ASA.

 

I've done this in the past with an ASA and I know it works, but I'm not sure if it works with Palo Alto. Does anyone have a senerio like this configured?

 

Thanks,

 

S.

5 REPLIES 5

L7 Applicator

It sounds like you need a security policy to permit the dhcp reply on the PA.  This would be from the zone of the tunnel interface to the zone where the client is connected to the network.

 

Steve Puluka BSEET - IP Architect - DQE Communications (Metro Ethernet/ISP)
ACE PanOS 6; ACE PanOS 7; ASE 3.0; PSE 7.0 Foundations & Associate in Platform; Cyber Security; Data Center

Hi Pulukas,

 

I have them both on the trusted zone for simplicity. Do I still need a rule?

The default intrazone policy is to permit so if that has not been overridden it should work.  You can confirm the deployed rule.

 

https://live.paloaltonetworks.com/t5/Management-Articles/What-are-Universal-Intrazone-and-Interzone-...

 

Or just create an explict one for this traffic so you can see session init logs confirming the traffic arrives on the PA.

 

If the logs don't help we can try packet captures to confirm what is happening.

Steve Puluka BSEET - IP Architect - DQE Communications (Metro Ethernet/ISP)
ACE PanOS 6; ACE PanOS 7; ASE 3.0; PSE 7.0 Foundations & Associate in Platform; Cyber Security; Data Center

L2 Linker

Hi 

 

Please attachet some pic to your main PA configurtion for DHCP Server and DHCP Relay

Will do. When I get back. Have to run to one of our remote sites for 2 weeks.

  • 4595 Views
  • 5 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!