Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    PFsense with downstream router and transit while still using DHCP on PFsense

    General pfSense Questions
    4
    12
    1.7k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • DerelictD
      Derelict LAYER 8 Netgate
      last edited by

      pfSense DHCP does not support that. There are no GUI widgets to support serving multiple subnets on one interface like that.

      ISC DHCP server should support it just fine.

      You might have to roll your own DHCP server if you can't use MS.

      Never heard of a Layer 3 switch without DHCP server capability. You might want to look again there.

      Chattanooga, Tennessee, USA
      A comprehensive network diagram is worth 10,000 words and 15 conference calls.
      DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
      Do Not Chat For Help! NO_WAN_EGRESS(TM)

      1 Reply Last reply Reply Quote 0
      • C
        coxhaus
        last edited by

        DHCP is a broadcast.  If you want to relay to another network the broadcast, you use DHCPRELAY or ip helper address depending on your equipment.  I would want all my DHCP ip addresses in one location for easy access.  Microsoft makes a nice DHCP server and DNS server which works well with Microsoft Active Directory.

        1 Reply Last reply Reply Quote 0
        • DerelictD
          Derelict LAYER 8 Netgate
          last edited by

          OP doesn't want to be subject to the CALs, though I find it hard to believe the CALs wouldn't be somehow applicable in some other manner.

          Chattanooga, Tennessee, USA
          A comprehensive network diagram is worth 10,000 words and 15 conference calls.
          DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
          Do Not Chat For Help! NO_WAN_EGRESS(TM)

          1 Reply Last reply Reply Quote 0
          • P
            pithychats
            last edited by

            @Derelict:

            pfSense DHCP does not support that. There are no GUI widgets to support serving multiple subnets on one interface like that.

            ISC DHCP server should support it just fine.

            You might have to roll your own DHCP server if you can't use MS.

            Never heard of a Layer 3 switch without DHCP server capability. You might want to look again there.

            I am pretty sure the switch doesn't; people whine about it online.

            What if I made a separate DHCP instance for each VLAN. IE run a separate DHCP instance on VLAN10 and VLAN20. I have done that in the past and it seems to work. For the CALs, the problem is MS wants a CAL for everything, including printers, people on guest wireless etc. For many of these clients the only item requiring a CAL is DHCP.

            If I do roll my own DHCP server (which is definitely doable, I can just spin up an CentOS instance), how do I set the NATing for downstream subnets?

            Thanks for the help

            1 Reply Last reply Reply Quote 0
            • johnpozJ
              johnpoz LAYER 8 Global Moderator
              last edited by

              "I am pretty sure the switch doesn't; people whine about it online."

              What switch?  Make and model.. I find it almost impossible to fathom a L3 switch not supporting dhcp..

              An intelligent man is sometimes forced to be drunk to spend time with his fools
              If you get confused: Listen to the Music Play
              Please don't Chat/PM me for help, unless mod related
              SG-4860 24.11 | Lab VMs 2.7.2, 24.11

              1 Reply Last reply Reply Quote 0
              • P
                pithychats
                last edited by

                @johnpoz:

                "I am pretty sure the switch doesn't; people whine about it online."

                What switch?  Make and model.. I find it almost impossible to fathom a L3 switch not supporting dhcp..

                HP 6600-24G-4XG. I cannot find anything about it supporting a DHCP server in the documentation.

                I am still curious about the setup though. Is there an technical reason I cannot route VLAN traffic over 1 trunk from the L3 switch and everything else over the transit link? I am also still a bit confused as to how to deal with downstream NAT.

                Thanks!

                1 Reply Last reply Reply Quote 0
                • DerelictD
                  Derelict LAYER 8 Netgate
                  last edited by

                  It is not routing that is the problem. It is DHCP.

                  pfSense-Layer-3-Switch.png
                  pfSense-Layer-3-Switch.png_thumb

                  Chattanooga, Tennessee, USA
                  A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                  DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                  Do Not Chat For Help! NO_WAN_EGRESS(TM)

                  1 Reply Last reply Reply Quote 0
                  • C
                    coxhaus
                    last edited by

                    My Cisco SG300-28 layer 3 switch supports DHCP for multiple networks.  I use it.

                    1 Reply Last reply Reply Quote 0
                    • DerelictD
                      Derelict LAYER 8 Netgate
                      last edited by

                      If you set a gateway on a LAN interface and route subnets to it, pfSense should pick that up and properly do outbound NAT for it on its WAN interfaces. If you hit a situation where that is not the case, hybrid or manual outbound NAT will be able to solve it.

                      Chattanooga, Tennessee, USA
                      A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                      DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                      Do Not Chat For Help! NO_WAN_EGRESS(TM)

                      1 Reply Last reply Reply Quote 0
                      • johnpozJ
                        johnpoz LAYER 8 Global Moderator
                        last edited by

                        Sure looks like it supports being a dhcp server to me!

                        http://h20566.www2.hpe.com/portal/site/hpsc/template.PAGE/action.process/public/psi/manualsDisplay/?sp4ts.oid=3897494&javax.portlet.action=true&spf_p.tpst=psiContentDisplay&javax.portlet.begCacheTok=com.vignette.cachetoken&spf_p.prp_psiContentDisplay=wsrp-interactionState%3DdocId%253Demr_na-c04490719%257CdocLocale%253Den_US&javax.portlet.endCacheTok=com.vignette.cachetoken

                        Did you actually go over the management and configuration guide?

                        dhcpserver.png
                        dhcpserver.png_thumb

                        An intelligent man is sometimes forced to be drunk to spend time with his fools
                        If you get confused: Listen to the Music Play
                        Please don't Chat/PM me for help, unless mod related
                        SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                        1 Reply Last reply Reply Quote 0
                        • P
                          pithychats
                          last edited by

                          @johnpoz:

                          Sure looks like it supports being a dhcp server to me!

                          http://h20566.www2.hpe.com/portal/site/hpsc/template.PAGE/action.process/public/psi/manualsDisplay/?sp4ts.oid=3897494&javax.portlet.action=true&spf_p.tpst=psiContentDisplay&javax.portlet.begCacheTok=com.vignette.cachetoken&spf_p.prp_psiContentDisplay=wsrp-interactionState%3DdocId%253Demr_na-c04490719%257CdocLocale%253Den_US&javax.portlet.endCacheTok=com.vignette.cachetoken

                          Did you actually go over the management and configuration guide?

                          Thanks. It turn out hp.com had an older version of the manual. A firmware update allowed DHCP to work. Thanks again to everyone for the help!

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.