- CheckMates
- :
- Products
- :
- Quantum
- :
- Remote Access VPN
- :
- R82 DHCP office mode setup
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
R82 DHCP office mode setup
Hey guys,
Im attaching a doc I put together with bunch of screenshot/troubleshooting steps I had taken so far to try make dhcp office mode work in R82 lab. I feel Im getting close, but hopefully once I have another TAC remote session, we finally get it going.
This is related to my post below.
I will update the doc as I go along.
Lab details:
R82 standalone - 172.16.10.253, R82 jumbo 10
DHCP server - windows server 2022 - 172.16.10.199 (latest windows update installed, windows fw turned off)
dhcp scope - 10.20.30.1-10.20.30.254
exclusion - vip address 10.20.30.1
allow list on dhcp server - whatever mac address is listed by running vpn macutil andy (thats my local vpn user) and tcpdump from the gateway, filtering for dhcp server ip and ports 67 and 68
Best,
Andy
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Here is the fix in case anyone has this problem.
Andy
IMPORTANT, that was sadly missing.
Andy
-
In Virtual IP address for DHCP server replies, enter an IP address from the sub network of the IP addresses which are designated for Office Mode usage.
Office Mode supports DHCP Relay method for IP assignment, so you can direct the DHCP server as to where to send its replies. The routing on the DHCP server and that of internal routers must be adjusted so that packets from the DHCP server to this address are routed through the Security Gateway.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Have not tried same in R81.20, but will try that if I can get R82 working first.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Quick update...had lengthy RS with lady from Ottawa TAC and she was extremelly nice AND helpful! We did bunch of debugs and checked logs on dhcp server, though now we keep seeing discover and offer, but no response or acknowledge for dhcp. She told me would ask around to see how this can be solved in my R82 lab. I will keep updating the document and post it again once we find the solution.
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Here is the fix in case anyone has this problem.
Andy
IMPORTANT, that was sadly missing.
Andy
-
In Virtual IP address for DHCP server replies, enter an IP address from the sub network of the IP addresses which are designated for Office Mode usage.
Office Mode supports DHCP Relay method for IP assignment, so you can direct the DHCP server as to where to send its replies. The routing on the DHCP server and that of internal routers must be adjusted so that packets from the DHCP server to this address are routed through the Security Gateway.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Another, I feel is super IMPORTANT step, because if mac address entries are not in allowed list, I am unable to connect. If its local vpn user, you get this by running whatever username is, example (my username is andy). The other mac address is for 2nd user I added as a test. Other 2 are broadcast and universal mac, but they are not needed, I just had them there from previous testing.
[Expert@R82:0]# vpn macutil andy
DA-41-BC-EF-F9-7B, "andy"
[Expert@R82:0]#
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
LATEST UPDATED document...apologies for so many screnshots, but I feel it was needed.
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hey everyone,
Forgot to add another important point. Once you reboot dhcp server, you would NOT be able to reconnect, so you have to make sure route is added as PERMANENT, like one I did as below:
route add -p 10.20.30.0 MASK 255.255.255.0 172.16.10.253
10.20.30.0 is OM net and 172.16.10.253 my gw IP
Andy
