• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

[Solved] Active directory, multiple VLANS : DHCP and DHCP relay

Scheduled Pinned Locked Moved DHCP and DNS
5 Posts 2 Posters 823 Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • T
    Tommyboy
    last edited by Tommyboy Mar 18, 2024, 8:40 AM Mar 18, 2024, 7:55 AM

    Hi,
    I have started VLAN'ing our company network. The router is a Netgate sg-3100. We have a Windows based AD-domain. I've started by adding a Guest VLAN to our existing network. As I want to keep this VLAN as separated as possible from our main network, the Pfsense router is acting as DHCP server for this Guest VLAN. In our main VLAN, the Windows Server 2016 is acting as DCHP and DNS server.
    Now I would like to add a new OT-VLAN (for computers in our production environment). As I understood, the advised way to work is using DHCP relay, so that the DHCP requests from the computers in the OT-VLAN, reach our Windows DHCP server, and then setup a separate DCHP scope for this VLAN.
    Now I just found out that pfsense can't have the DHCP server service, and the DHCP relay service, running simultaneously. So one has to go.
    I can see several options :

    • Install a separate DCHP server on our Guest VLAN, so that Pfsense doesn't have to run the DHCP service anymore. That way I can use the relay service. Downside is that I need an additional server (physical or VM).
    • Use the pfsense DHCP service as well for the OT-VLAN. Is this a problem? I've read that it is best practice to let Windows server act as DHCP server for its entire domain.

    What would be the best way to go?

    N 1 Reply Last reply Mar 18, 2024, 8:10 AM Reply Quote 0
    • N
      NightlyShark @Tommyboy
      last edited by NightlyShark Mar 18, 2024, 8:11 AM Mar 18, 2024, 8:10 AM

      @Tommyboy You can make the AD Server VLAN-aware and turn its switch port in to a trunk that has the OT and Main VLANS, disable PfSense DHCP server (and DNS) on OT VLAN, voila.

      T 1 Reply Last reply Mar 18, 2024, 8:29 AM Reply Quote 0
      • N
        NightlyShark
        last edited by Mar 18, 2024, 8:21 AM

        e695351a-0e31-4971-937a-52dc7f4c090c-image.png

        1 Reply Last reply Reply Quote 0
        • T
          Tommyboy @NightlyShark
          last edited by Mar 18, 2024, 8:29 AM

          @NightlyShark
          Great! thanks for you answer! That solves everything 👍.

          Thx!

          N 1 Reply Last reply Mar 18, 2024, 8:35 AM Reply Quote 1
          • N
            NightlyShark @Tommyboy
            last edited by Mar 18, 2024, 8:35 AM

            @Tommyboy Please don't forget to mark the post as solved, happy networking!

            1 Reply Last reply Reply Quote 1
            5 out of 5
            • First post
              5/5
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
              This community forum collects and processes your personal information.
              consent.not_received