To configure DHCP over VPN Remote Gateway
Click Configure.
On the General screen, the VPN policy name is automatically displayed in the Relay DHCP through this VPN Tunnel field if the VPN policy has the setting Local network obtains IP addresses using DHCP through this VPN Tunnel enabled.
Only VPN policies using IKE can be used as VPN tunnels for DHCP. The VPN tunnel must use IKE and the local network must be set appropriately. The local network obtains IP addresses using DHCP through this VPN Tunnel.
If you enter an IP address in the Relay IP Address field, this IP address is used as the DHCP Relay Agent IP address (giaddr) in place of the Central Gateway’s address and must be reserved in the DHCP scope on the DHCP server. This address can also be used to manage this firewall remotely through the VPN tunnel from behind the Central Gateway.
The Relay IP address and Remote Management IP Address fields cannot be zero if management through the tunnel is required.
To configure devices on your LAN, click Devices.
To configure Static Devices on the LAN, click +Add to display the Add LAN Devices Entry dialog.
Type the IP address of the device in the IP Address field and then type the Ethernet address of the device in the Ethernet Address field.
An example of a static device is a printer as it cannot obtain an IP lease dynamically. If you do not have Block traffic through tunnel when IP spoof detected enabled, it is not necessary to type the Ethernet address of a device. You must exclude the Static IP addresses from the pool of available IP addresses on the DHCP server so that the DHCP server does not assign these addresses to DHCP clients. You should also exclude the IP address used as the Relay IP Address. It is recommended to reserve a block of IP address to use as Relay IP addresses.
Click OK to exit the DHCP over VPN Configuration dialog.
You must configure the local DHCP server on the remote firewall to assign IP leases to these computers.
If a remote site has trouble connecting to a central gateway and obtaining a lease, verify that Deterministic Network Enhancer (DNE) is not enabled on the remote computer.
If a static LAN IP address is outside of the DHCP scope, routing is possible to this IP, that is, two LANs.
Wireless clients are assigned an IP address in this subnet. The IP address and a DHCP server are automatically created and assign DHCP addresses.