DrayTek UK Users' Community Forum

Help, Advice and Solutions from DrayTek Users

2862 SSL VPN and external DHCP server

  • hopkins35
  • Topic Author
  • User
  • User
More
12 Jun 2018 08:53 #1 by hopkins35
2862 SSL VPN and external DHCP server was created by hopkins35
Hi all

Is it possible to have SSL VPN clients obtain their IP address from an external DHCP server, my setup is such that a VPN client joins LAN1 which is configured to use my Windows DHCP server, however when a client connects they're allocated an IP by the DHCP server on the 2862. As a workaround I've tweaked the address pools to avoid them overlapping but ideally I'd like them to be allocated by my external DHCP server.

Any help gratefully received, thanks

Please Log in or Create an account to join the conversation.

More
12 Jun 2018 15:13 #2 by sheltons
Replied by sheltons on topic Re: 2862 SSL VPN and external DHCP server

hopkins35 wrote: Hi all

Is it possible to have SSL VPN clients obtain their IP address from an external DHCP server, my setup is such that a VPN client joins LAN1 which is configured to use my Windows DHCP server, however when a client connects they're allocated an IP by the DHCP server on the 2862. As a workaround I've tweaked the address pools to avoid them overlapping but ideally I'd like them to be allocated by my external DHCP server.

Any help gratefully received, thanks



In the LAN setting there is a 'Enable Relay Agent' under the DHCP section, then set the DHCP to you Windows DHCP IP.

I have to say though, if you have DHCP enable on the sam subnet as a Windows DHCP then generally the Windows DHCP will shutdown.

Also I have had issues with VPN's getting IP's from Windows Servers, it looks like it times out before getting the IP. There is another thread on this and Draytek are looking in to it.

It's in the VPN Section: https://forum.draytek.co.uk/viewtopic.php?f=8&t=22086

John.

Please Log in or Create an account to join the conversation.

  • hopkins35
  • Topic Author
  • User
  • User
More
12 Jun 2018 15:29 #3 by hopkins35
Replied by hopkins35 on topic Re: 2862 SSL VPN and external DHCP server

Sheltons wrote:

hopkins35 wrote: Hi all

Is it possible to have SSL VPN clients obtain their IP address from an external DHCP server, my setup is such that a VPN client joins LAN1 which is configured to use my Windows DHCP server, however when a client connects they're allocated an IP by the DHCP server on the 2862. As a workaround I've tweaked the address pools to avoid them overlapping but ideally I'd like them to be allocated by my external DHCP server.

Any help gratefully received, thanks



In the LAN setting there is a 'Enable Relay Agent' under the DHCP section, then set the DHCP to you Windows DHCP IP.

I have to say though, if you have DHCP enable on the sam subnet as a Windows DHCP then generally the Windows DHCP will shutdown.

Also I have had issues with VPN's getting IP's from Windows Servers, it looks like it times out before getting the IP. There is another thread on this and Draytek are looking in to it.

It's in the VPN Section: https://forum.draytek.co.uk/viewtopic.php?f=8&t=22086

John.



Thanks John, I'd previously tried the relay agent setting and it didn't help in this instance.

Interesting that you should mention the conflict between the Draytek DHCP server and a Windows server because this is where I find the Draytek config confusing, I have the Draytek DHCP server turned off in the LAN1 settings which I thought would force the VPN client to obtain a lease from one of my two Windows servers however there's a setting in the menu VPN and Remote Access >> PPP General Setup >> IP Address Assignment for Dial-In Users (When DHCP Disable set) which seems to create a static pool of IP addresses to be allocated. I wish there was an option to disable this pool and force a client to obtain an IP from an external server!

Please Log in or Create an account to join the conversation.

More
12 Jun 2018 15:59 #4 by sheltons
Replied by sheltons on topic Re: 2862 SSL VPN and external DHCP server
I agree.

I had a look in the DHCP logs and every time I try a VPN to LAN1 with Assign Static turned off I get a 'NACK' entry.

What I have done due to low number of Remote VPNs is put an exclusion range for 230 - 240 in Windows DHCP and then in the Remote VPN profiles allocate a unique IP from 230, as in 10.0.8.230, 10.0.8.231 etc.

This works for me until a fix comes along, but if you have a lot of Remote VPN's then this would be a ball ache.

Please Log in or Create an account to join the conversation.