How can I create a DHCP lease scope dedicated for GVC clients not bound to any interface?
09/21/2023 655 People found this article helpful 493,833 Views
Description
This article describes how to create a DHCP dynamic lease scope without binding it to any interface of the SonicWall UTM appliance.
Such a lease scope can have an IP address range not configured on any interface of the SonicWall. This would be helpful in environments where the administrator requires GVC users to have IP addresses in a SEPARATE subnet.
Resolution
Resolution for SonicOS 7.X
This release includes significant user interface changes and many new features that are different from the SonicOS 6.5 and earlier firmware. The below resolution is for customers using SonicOS 7.X firmware.
Under WAN GroupVPN | Client | Client CONNECTIONS | Virtual Adapter setting set DHCP Lease.
To create a separate DHCP range where the dhcp server will be the Sonciwall firewall use DHCP Configuration in SonicWall.
- Login to your SonicWall management page and click Manage tab on top of the page.
- Navigate to Network | System | DHCP Server settings page, make sure Enable DHCPv4 Server checkbox enabled.
- Click Add Dynamic button under DHCPv4 Server Lease Scopes section to get DHCP Server Configuration window.
- Update correct Range Start & Range End along with Default Gateway (Including subnet mask). Configure a different DHCP range instead of interface assigned subnet.
- Click OK .
NOTE: Do not enable the check box Interface Pre-Populate.
- New DHCP Scope will be created as below with interface as N/A
By using the Relay IP Address option with an interface independent DHCP Lease Scope, GVC clients can be served IP Addresses from the dedicated pool above. To use this DHCP scope for GVC clients, perform the following:
DHCP over VPN Settings:
- Navigate to the Network | IPSec VPN | DHCP over VPN page.
- Click Configure under Central Gateway to bring up the DHCP over VPN Configuration.
- Enable check box Use Internal DHCP Server.
- Enable check box For Global VPN Client.
- Enter an IP address outside the DHCP scope defined above under Relay IP Address.
Following the above configuration, GVC clients will be leased an IP address from the range 192.168.10.x. If VPN Access List is configured, GVC users will be able to access the resource/s added in it.
Resolution for SonicOS 6.5
This release includes significant user interface changes and many new features that are different from the SonicOS 6.2 and earlier firmware. The below resolution is for customers using SonicOS 6.5 firmware.
Under WAN GroupVPN | Client | Client CONNECTIONS | Virtual Adapter settingenable DHCP Lease.
To create a separate DHCP range where the dhcp server will be the Sonciwall firewall use DHCP Configuration in SonicWall.
- Login to your SonicWall management page and click Manage tab on top of the page.
- Navigate to Network | DHCP Server settings page, make sure Enable DHCPv4 Server checkbox enabled.
- Click Add Dynamic button under DHCPv4 Server Lease Scopes section to get DHCP Server Configuration window.
- Update correct Range Start & Range End along with Default Gateway (Including subnet mask). Configure a different DHCP range instead of interface assigned subnet.
- Click OK .
NOTE: Do not enable the check box Interface Pre-Populate.
- New DHCP Scope will be created as below with interface as N/A.
By using the Relay IP Address option with an interface independent DHCP Lease Scope, GVC clients can be served IP Addresses from the dedicated pool above. To use this DHCP scope for GVC clients, perform the following:
DHCP over VPN Settings:
- Navigate to Manage tab and go to VPN | DHCP over VPN page.
- Under DHCP over VPN section, Select Central Gateway from drop-down box and click Configure button.
- In DHCP over VPN Configuration Window, enable Use Internal DHCP Server checkbox.
- Enable For Global VPN Client checkbox.
- Relay IP Address (optional): Add one of the IP address under for DHCP over VPN configurations.
- Click OK .
Following the above configuration, GVC clients will be leased an IP address from the range 192.168.10.x. If VPN Access List is configured, GVC users will be able to access the resource/s added in it.
There are two ways to contact technical support:
1. Online: Visit mysonicwall.com. Once logged in select Resources & Support | Support | Create Case.
2. By phone: please use our toll-free number at 1-888-793-2830. Please have your SonicWall serial number available to create a new support case.
If you do not have a mysonicwall.com account create one for free!
Related Articles
Categories