Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    DHCP relay for only one VLAN

    Routing and Multi WAN
    3
    4
    665
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • R
      russm
      last edited by

      We're in the process of retiring our old HP Procurve 5412zl. One of the functions of this beast was to act as a "dhcp-helper" and point the clients from one specific vlan to a Windows domain controller on our server vlan. We have 15 other vlans that all use pfsense for their DHCP server, and have no access to any of the client/server networks. We'd like to keep those vlans away from our client/server vlans. Can I set up a second virtual pfsense for only doing the DHCP relay for the client vlan? If so, what does that configuration look like?

      Thanks,
      Russ

      V 1 Reply Last reply Reply Quote 0
      • V
        viragomann @russm
        last edited by

        @russm said in DHCP relay for only one VLAN:

        We have 15 other vlans that all use pfsense for their DHCP server, and have no access to any of the client/server networks. We'd like to keep those vlans away from our client/server vlans.

        Why won't you allow only DHCP access and nothing else?

        Can I set up a second virtual pfsense for only doing the DHCP relay for the client vlan?

        Never tried that, but I think it should work, since the DHCP clients just broadcast the requests and then use the servers (relays) IP to communicate. This needs not to be the gateway.
        So just give it a network interface with IPs in both subnets.

        R 1 Reply Last reply Reply Quote 1
        • R
          russm @viragomann
          last edited by

          @viragomann The security guys don't want non-client/server specific vlans accessing any part of the server vlan. I did find a ubuntu package that runs a dhcp agent that can re-point clients to the proper server. I'll be investigating that later today.

          bingo600B 1 Reply Last reply Reply Quote 0
          • bingo600B
            bingo600 @russm
            last edited by

            @russm
            You would use the DHCP Relay function for that, you can enable "per inteface".
            I use it to forward my Vlans to a Linux DHCP server.

            Note . DHCP Server & DHCP Relay are mutually exclusive.
            So you'd need a "new pfsense instance" , as you mention ... Since you're already runnĆ­ng DHCP server on your prod box.

            If you find my answer useful - Please give the post a šŸ‘ - "thumbs up"

            pfSense+ 23.05.1 (ZFS)

            QOTOM-Q355G4 Quad Lan.
            CPUĀ  : Core i5 5250U, Ram : 8GB Kingston DDR3LV 1600
            LANĀ  : 4 x Intel 211, DiskĀ  : 240G SAMSUNG MZ7L3240HCHQ SSD

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.