Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    How to Block DHCP Requests

    Scheduled Pinned Locked Moved Firewalling
    3 Posts 3 Posters 4.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • J
      jmarcum
      last edited by

      I have two internal networks connected to pfSense. Each network has its own active directory domain with DNS and DHCP. How would I setup a firewall rule to block dhcp requests between the two networks? My DHCP clients on network 2 get DHCP from network 1 as I have it now. I've also had issues authorizing DNS and DHCP in the domain on network 2. I think it's seeing the AD forest on network 1 and thinking it's not authorized.

      1 Reply Last reply Reply Quote 0
      • KOMK
        KOM
        last edited by

        Block UDP port 67 between the two networks.

        1 Reply Last reply Reply Quote 0
        • jimpJ
          jimp Rebel Alliance Developer Netgate
          last edited by

          DHCP operates using IPv4 broadcasts at layer 2. It is not capable of traversing between segments if they are actually separate, and you cannot have two distinct DHCP servers inside the same layer 2 broadcast/collision domain.

          If two segments can see DHCP from each other then:

          1. Both segments are using the same flat switch. Don't do that. Use separate switches or VLANs.
          2. There is some other cable or bridge linking the switches together. Find and remove it.
          3. pfSense is bridging between the segments. Not something you'd generally want to do, but not out of line. In this case, add a firewall rule to block it.

          Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

          Need help fast? Netgate Global Support!

          Do not Chat/PM for help!

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.