Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    DHCP Relay over OpenVPN tunnel

    Scheduled Pinned Locked Moved DHCP and DNS
    3 Posts 2 Posters 3.0k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • A Offline
      AaronTS
      last edited by

      I have a site-to-site VPN tunnel that works great, everyone can communicate properly. On the OpenVPN server side router, I have multiple VLANs each on their own subnet, and I have DHCP relay enabled pointing to my DHCP server. That works great too, each client gets an IP from the appropriate range.

      The problem comes in with my remote site on the other end of the OpenVPN tunnel. Even though I enable DHCP relay with the same settings pointed to the same server, no devices on the remote end can get an IP from the DHCP server. If manually assigned an IP they can ping the DHCP server, and can connect to other services on the DHCP server, but the DHCP relay is not working.

      Is there an additional setting I am missing to enable DHCP relay over the OpenVPN tunnel?

      Thank you in advance for your help!

      1 Reply Last reply Reply Quote 0
      • A Offline
        AaronTS
        last edited by

        As I read more about this, it sounds like DHCP Relay may not be supported in TUN mode as I have it set up, and that I have to use TAP. Is DHCP Relay possible over TUN or am I trying to do something not supported?

        1 Reply Last reply Reply Quote 0
        • jimpJ Offline
          jimp Rebel Alliance Developer Netgate
          last edited by

          It may work (I haven't tried it) but keep in mind pfSense will originate the relay requests from the IP address of the tun interface in this case.

          I know for certain it doesn't work properly with IPsec.

          If you have a managed switch, check and see if it has an "IP Helper" or DHCP relay function and enable it there rather than on the firewall.

          Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

          Need help fast? Netgate Global Support!

          Do not Chat/PM for help!

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.