Hello Community,
we have the following construct:
Our Sophos is a SG450 with Version: 9.510-5
The Sophos Gateway routes the traffic for VLAN 144 and holds the interface on an link aggregation group.
From the link aggregation group the traffic is routed through a transfer network to our core switches (Transfer-Network via VLAN2101)
Our Core-Switches routes the traffic for VLAN 16 (Servernetwork). In this network is the PXE-Server hosted (10.46.16.40) and the DHCP-Server (10.46.16.8)
Now if we want to image a laptop via PXE Boot the Boot ends in the DHCP-Handshake at: DHCP Offer. No DHCP Request and Acknowledge is applied to the client.
I know that if the DHCP-Server, TFTP-Server and Client in different VLANs/Subnets its not so easy with PXE Boot.
I analyzed the traffic while the client pc tries to boot up with tcpdump on the transfer network between firewall and core-switches:
TCPDump:
DHCP-Scope (MS DHCP-Server) Settings:
Interfaces on Sophos - DHCP-Relaying for Interface VLAN144:
ICMP-Settings in Firewall:
In the Firewall log there weren't any Drops.
Core-Switch VLAN 2101 - ip helper-addresses
(Trk1-Trk2) --> LAG to Sophos
Core-Switch VLAN 144 - ip helper-addresses
The only idea that i have is that i dont relay the DHCP-Traffic for VLAN144 to the MS-DHCP-Servers.
Instead of this i could setup an DHCP-Server in the Sophos for VLAN 144 and set there the DHCP-Options,
with that the Client PC can find the TFTP-Server.
Any ideas?
Thank so far!
This thread was automatically locked due to age.