Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Moudar
MVP Silver
MVP Silver
Jump to solution

A Thought about the DHCP server on the gateway

Hi,

We are currently using the gateway as a DHCP server for several guest networks.

In certain cases, we need to assign (reserve) a specific IP address to a specific client MAC address for operational reasons. However, I was unable to find any option in the Gaia Portal under DHCP settings that allows reserving an IP address for a particular MAC.

The only method I could find was to manually edit the /etc/dhcpd.conf file and add a static mapping for the desired MAC address. This approach works, but the problem is that in order for the changes to persist after a reboot, the file must be set as immutable.

This introduces a new issue:
Today, we needed to add a new DHCP scope for a new interface on the gateway. We went through the Gaia Portal as usual, created and enabled the new DHCP server, but noticed that none of the clients could obtain an IP address.

After troubleshooting, we checked the /etc/dhcpd.conf file and discovered that it did not include the new DHCP configuration we had just created. The reason was that the file was set as immutable, preventing Gaia from writing new configuration changes.

What’s confusing is that the Gaia Portal did not provide any warning or indication that the file was immutable or that the configuration changes would not take effect. The interface appeared normal, but in practice, DHCP was not functioning.

Therefore, I have two main questions:

  1. Is there a supported way to reserve (bind) a specific IP address to a specific MAC address directly from the Gaia Portal or via the Check Point CLI (without manually editing /etc/dhcpd.conf)?

  2. Why does the Gaia Portal not provide a warning when attempting to apply DHCP configuration changes while the /etc/dhcpd.conf file is immutable and therefore cannot be updated?

I’m not an expert on this topic, so I’m genuinely curious about how this is intended to work — and what the recommended best practice is in such cases.

Any ideas or suggestions are very welcome!

0 Kudos
1 Solution

Accepted Solutions
Lesley
MVP Gold
MVP Gold

1. -> No 😉 RFE would be needed

2. -> I have send the following SK feedback: 

Please add a note in this SK that any DHCP server changes to GAIA OS are not performed when the /etc/dhcpd.conf is locked with immutable status to avoid the file being overwritten. More details are in:

https://community.checkpoint.com/t5/Security-Gateways/A-Thought-about-the-DHCP-server-on-the-gateway...
https://community.checkpoint.com/t5/Security-Gateways/CAUTION-when-configuring-DHCP-options/td-p/113...

This process is written in: https://support.checkpoint.com/results/sk/sk60001 step: Support center

-------
Please press "Accept as Solution" if my post solved it 🙂

View solution in original post

3 Replies
the_rock
MVP Platinum
MVP Platinum

From what I know, that is indeed the only way, but maybe someone else can confirm.

Andy

Best,
Andy
0 Kudos
Lesley
MVP Gold
MVP Gold

1. -> No 😉 RFE would be needed

2. -> I have send the following SK feedback: 

Please add a note in this SK that any DHCP server changes to GAIA OS are not performed when the /etc/dhcpd.conf is locked with immutable status to avoid the file being overwritten. More details are in:

https://community.checkpoint.com/t5/Security-Gateways/A-Thought-about-the-DHCP-server-on-the-gateway...
https://community.checkpoint.com/t5/Security-Gateways/CAUTION-when-configuring-DHCP-options/td-p/113...

This process is written in: https://support.checkpoint.com/results/sk/sk60001 step: Support center

-------
Please press "Accept as Solution" if my post solved it 🙂
the_rock
MVP Platinum
MVP Platinum

Thanks for confirming @Lesley 

Best,
Andy
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events