Screen OS

last person joined: 8 months ago 

This is a legacy community with limited Juniper monitoring.
  • 1.  SSG5 dhcp server for subnet not directly connected

    Posted 04-25-2012 04:34

    Hi, is it possible to setup the ssg5 as dhcp server for subnets not direclty connected to the ssg5?

     

    All examples I found so far say nothing about it (and actually configuration I tried so far is not working).

     

    Thanks for any help.



  • 2.  RE: SSG5 dhcp server for subnet not directly connected

    Posted 05-02-2012 00:48

    Hi,

     

    Your question relates rather to the ability of the device in the middle to relay the dhcp requests. But if these requests are relayed as unicasts the ssg will not process them.



  • 3.  RE: SSG5 dhcp server for subnet not directly connected

    Posted 05-03-2012 04:46

    Hi,

     

    ok thank you.

     

    The topology looks like this

     

    |dhcp client| - |fw/router dhcp relay| - |ssg5 dhcp server|

     

    Yes the ssg5 will receive the requestes as unicast, and when I understood correct, will not process them.



  • 4.  RE: SSG5 dhcp server for subnet not directly connected
    Best Answer

    Posted 05-03-2012 05:28

    Hi,

     

    Yes, you understood this correctly.

    As stated in the KB19962:

     

    The ScreenOS firewall responds to only broadcast DHCP Discover messages. It does not address unicast DHCP request packets (mostly from Relay Agents). DHCP functionality is just an add-on provided on the firewall. It cannot act as an full fledge DHCP server. This is by design.