I don't think GP supports giving addresses to clients via DHCP. When clients connect to the gateway, they're forming a point-to-point tunnel. This tunnel has an IP address and a subnet mask of 255.255.255.255 that the client uses to identify the tunnel, and the tunnel interface on the firewall may not even have an IP address to use as a default gateway. It's not quite the same as just handing the client an address, subnet mask, gateway, etc. from DHCP in a traditional layer 3 network. These forum posts, while older, seem to support this, and I have never seen any documentation about using DHCP instead of IP pools on GP. https://live.paloaltonetworks.com/t5/general-topics/dhcp-relay-for-globalprotect/td-p/205699 https://live.paloaltonetworks.com/t5/general-topics/global-protect-dhcp-config/td-p/228635
... View more