<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Office Mode IP allocation for VPN users from DHCP server in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Office-Mode-IP-allocation-for-VPN-users-from-DHCP-server/m-p/178534#M7585</link>
    <description>&lt;P&gt;Unless we happen to have knowledge of an RFE through other means (e.g. SK articles), the community team has no visibility into RFEs.&amp;nbsp;&lt;BR /&gt;The best course of action is to engage with your local Check Point office.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 19 Apr 2023 17:39:54 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2023-04-19T17:39:54Z</dc:date>
    <item>
      <title>Office Mode IP allocation for VPN users from DHCP server</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Office-Mode-IP-allocation-for-VPN-users-from-DHCP-server/m-p/135715#M7581</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;While implementing OM IP allocation for VPN users, we discovered an issue with having a DHCP server allocate IP addresses.&amp;nbsp; We are running R81.&lt;/P&gt;&lt;P&gt;We have a pair of&amp;nbsp; Windows DHCP servers which distribute IP addresses to all different clients in the LAN (telephones and computers).&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;Checkpoint only allows defining one DHCP server in Office Mode configuration.&amp;nbsp; We chose one of the DHCP servers, but noticed that some users were not able to receive IP addresses (error appears on client and in logs).&amp;nbsp; When we switched to second DHCP server, clients that were able to receive from first server were now not able to have IP address allocated.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;It was not consistent.&amp;nbsp; Some users did succeed. Others did not.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&amp;nbsp;It took a while, but we found the cause of the problem:&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;I&gt;&lt;A title="" href="https://get-cmd.com/?p=3471" target="_blank" rel="noopener noreferrer"&gt;https://get-cmd.com/?p=3471&lt;/A&gt;&lt;/I&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;I&gt;&lt;SPAN class=""&gt;In DHCP failover, the client messages which are broadcast are received by both the DHCP failover servers. However, only one server responds to the client messages. In case of load balance mode, the servers will hash the MAC address of a DHCP client to establish which of them must respond. In hot standby mode, only the active server responds. In both cases, the DHCP server which does not respond to the client logs this message in the audit log.&lt;/SPAN&gt;&lt;/I&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;&amp;nbsp;&lt;STRONG&gt;I&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN class=""&gt;f the hash of the laptop belongs to the server not defined in the firewall, then IP allocation will fail.&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;For now, we have removed the scope from the second DHCP server, such that only one server will allocate IP addresses for the VPN OM scope.&amp;nbsp; This server is defined in Firewall OM configuration.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;There is a "hotstandby" option where the second DHCP will take over the scope only if the primary server fails.&amp;nbsp; However, the IP address of the DHCP in the firewall will still need to be changed manually.&amp;nbsp; We haven't found a fully automatic solution.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;Note:&amp;nbsp; When we configure DHCP Relay Addresses for LAN DHCP allocation, we configure both&amp;nbsp; DHCP servers.&amp;nbsp;&amp;nbsp; Since both receive the request, both will hash the MAC address and decide if to answer or not.&amp;nbsp; It is not possible to configure two DHCP ervers in Office Mode configuration.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class=""&gt;Maybe a feature request for Checkpoint.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Hope this helps someone.&lt;/P&gt;&lt;P&gt;micha&lt;/P&gt;</description>
      <pubDate>Tue, 07 Dec 2021 10:19:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Office-Mode-IP-allocation-for-VPN-users-from-DHCP-server/m-p/135715#M7581</guid>
      <dc:creator>mkushner</dc:creator>
      <dc:date>2021-12-07T10:19:06Z</dc:date>
    </item>
    <item>
      <title>Re: Office Mode IP allocation for VPN users from DHCP server</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Office-Mode-IP-allocation-for-VPN-users-from-DHCP-server/m-p/136230#M7582</link>
      <description>&lt;P&gt;This definitely sounds like an RFE.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Dec 2021 06:22:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Office-Mode-IP-allocation-for-VPN-users-from-DHCP-server/m-p/136230#M7582</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-12-14T06:22:54Z</dc:date>
    </item>
    <item>
      <title>Re: Office Mode IP allocation for VPN users from DHCP server</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Office-Mode-IP-allocation-for-VPN-users-from-DHCP-server/m-p/178345#M7583</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/58323"&gt;@mkushner&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;any news on this question, can you check if any kind of RFE has been submitted?&lt;/P&gt;&lt;P&gt;We are facing the same situation, that's why we are still sticking to the CP built-in DHCP. and not migrating to Windows DHCP.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Apr 2023 07:48:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Office-Mode-IP-allocation-for-VPN-users-from-DHCP-server/m-p/178345#M7583</guid>
      <dc:creator>Hrvoje_Brlek</dc:creator>
      <dc:date>2023-04-18T07:48:35Z</dc:date>
    </item>
    <item>
      <title>Re: Office Mode IP allocation for VPN users from DHCP server</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Office-Mode-IP-allocation-for-VPN-users-from-DHCP-server/m-p/178352#M7584</link>
      <description>&lt;P&gt;If you have a similar requirement definitely talk to your local CP SE about raising an RFE to help support it.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Apr 2023 08:42:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Office-Mode-IP-allocation-for-VPN-users-from-DHCP-server/m-p/178352#M7584</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-04-18T08:42:50Z</dc:date>
    </item>
    <item>
      <title>Re: Office Mode IP allocation for VPN users from DHCP server</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Office-Mode-IP-allocation-for-VPN-users-from-DHCP-server/m-p/178534#M7585</link>
      <description>&lt;P&gt;Unless we happen to have knowledge of an RFE through other means (e.g. SK articles), the community team has no visibility into RFEs.&amp;nbsp;&lt;BR /&gt;The best course of action is to engage with your local Check Point office.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Apr 2023 17:39:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Office-Mode-IP-allocation-for-VPN-users-from-DHCP-server/m-p/178534#M7585</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-04-19T17:39:54Z</dc:date>
    </item>
  </channel>
</rss>

